Terminal equipment, and digital cache management system
Abstract
Problem to be solved.To provide a data copyright and management system in a multimedia system. The data supplied from the database 1 to the users 4 to 9 is encrypted and distributed, and the user decrypts the encrypted data using an encryption key obtained from the key management center 9 or the copyright management center 10. Use. The data is re-encrypted when users 4-9 store, copy or transfer the data, but this key is supplied by the key management center 9 or the copyright management center 10 or generated by the copyright management program. .. [Selection diagram] Fig. 1
Term
Term ended
Projected expiry passed 12 September 2023, 3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
34 claims: 23 independent, 11 dependent
- 1A terminal device that manages the copyright of data supplied as encrypted data from a database to a user and communicates with such a copyright management system, and is a means for receiving a first private key from the copyright management system. And the means for receiving the encrypted data via the network, artificial satellite, or storage medium, and when the encrypted data is displayed, the encrypted data is decrypted using the first private key. The means for decrypting the data, the means for generating the second private key by the copyright management program supplied from the copyright management system, and the means for encrypting the displayed data into the re-encrypted data using the second private key. A terminal device characterized by being composed of means for converting data. データベースからユーザに暗号化データとして供給されるデータの著作権を管理する、そのような著作権管理システムと通信する端末装置であって、 前記著作権管理システムから第1秘密鍵の交付を受ける手段と、 前記ネットワーク、人口衛星、または記憶媒体を経由して暗号化データの供給を受ける手段と、 前記暗号化データが表示される場合に、前記第1秘密鍵を用いて暗号化データを復号データに復号する手段と、 前記著作権管理システムから供給された著作権管理プログラムにより第2秘密鍵を生成する手段と、 前記第2秘密鍵を用いてその表示されたデータを再暗号化データへ暗号化する手段と から構成されることを特徴とする端末装置。
- 3A terminal device that manages the copyright of data supplied as encrypted data from a database to a user and communicates with such a copyright management system, and is a means for receiving a first private key from the copyright management system. And the means for receiving the encrypted data via the network, artificial satellite, or storage medium, and when the encrypted data is processed, the encrypted data is decrypted using the first private key. Decryption means, means for generating a second private key by the copyright management program supplied from the copyright management system, and encryption of the processed data using the second private key into re-encrypted data. A terminal device characterized by being composed of means for converting data. データベースからユーザに暗号化データとして供給されるデータの著作権を管理する、そのような著作権管理システムと通信する端末装置であって、 前記著作権管理システムから第1秘密鍵の交付を受ける手段と、 前記ネットワーク、人口衛星、または記憶媒体を経由して暗号化データの供給を受ける手段と、 前記暗号化データが加工される場合に、前記第1秘密鍵を用いて暗号化データを復号データに復号する手段と、 前記著作権管理システムから供給された著作権管理プログラムにより第2秘密鍵を生成する手段と、 前記第2秘密鍵を用いてその加工されたデータを再暗号化データへ暗号化する手段と から構成されることを特徴とする端末装置。
- 5Claim 1 further includes means for presenting the primary user information of the terminal device to the copyright management system and requesting the use of the data, and means for adding the primary user information to the re-encrypted data. The terminal device according to any one of 4 to 4. 前記端末装置の1次ユーザ情報を前記著作権管理システムへ提示して前記データの利用を要求する手段と、 前記再暗号化データに前記1次ユーザ情報を付加する手段と をさらに備える請求項1から4のいずれかに記載の端末装置。
- 8A digital cache management system for using the encrypted digital cache supplied from the financial institution to the first user:in the digital cache management system, the decryption key of the encrypted digital cache data is the financial institution. The encrypted digital cache data is decrypted using the decryption key when the first user confirms the digital cache data;the first user is the first user. A digital cache management system in which the data is re-encrypted when the decrypted digital cache data is stored, when the modified digital cache data is stored, or when the digital cache data is transferred to a second user. 暗号化されて金融機関から第1利用者に供給されるディジタルキャッシュを利用するためのディジタルキャッシュ管理システムであって:該ディジタルキャッシュ管理システムにおいては、前記暗号化ディジタルキャッシュデータの復号鍵が金融機関から前記第1利用者に供給され;前記第1利用者が前記ディジタルキャッシュデータの確認を行う場合には前記復号鍵を用いて前記暗号化ディジタルキャッシュデータが復号され;前記第1利用者が前記復号化ディジタルキャッシュデータを保存する場合、変更されたディジタルキャッシュデータを保存する場合、あるいは第2利用者にディジタルキャッシュデータを転送する場合には前記データが再暗号化される、ディジタルキャッシュ管理システム。
- 14A digital cache management system for using the encrypted digital cache supplied by a financial institution to a first user:the digital cache management system uses an encryption key, user information and a digital cache management program. The first user presents the first user information to the financial institution;the financial institution supplies the first user with the digital cash encrypted with the first encryption key;the first use The person uses the digital cache management program to generate a second encryption key based on the first encryption key;when the first user confirms the encrypted digital cache data, the first encryption key. The encrypted digital cache data is decrypted using the;when the user stores the decrypted digital cache data, it is re-encrypted using the second encryption key;the decrypted digital cache data is When transferred to the second user, it is re-encrypted using the second encryption key, and the re-encrypted digital cache data is transferred to the second user together with the first user information;the second use. The first user information is presented to the financial institution by the person;the financial institution generates the second encryption key based on the first user information and transfers it to the second user;the second use. A digital cache management system in which a person decrypts the re-encrypted digital cache data by the digital cache management program using the transferred second encryption key. 暗号化されて金融機関から第1利用者に供給されるディジタルキャッシュを利用するためのディジタルキャッシュ管理システムであって:該ディジタルキャッシュ管理システムでは暗号鍵、利用者情報及びディジタルキャッシュ管理プログラムが利用され;前記第1利用者は前記金融機関に第1利用者情報を提示し;前記金融機関は前記第1利用者に第1暗号鍵で暗号化された前記ディジタルキャッシュを供給し;前記第1利用者は前記ディジタルキャッシュ管理プログラムを利用して前記第1暗号鍵に基づく第2暗号鍵を生成し;前記第1利用者が前記暗号化ディジタルキャッシュデータの確認を行う場合には前記第1暗号鍵を用いて前記暗号化ディジタルキャッシュデータが復号され;前記利用者が前記復号化ディジタルキャッシュデータを保存する場合には、前記第2暗号鍵を用いて再暗号化され;前記復号化ディジタルキャッシュデータが第2利用者に転送される時に前記第2暗号鍵を用いて再暗号化され、前記再暗号化ディジタルキャッシュデータが前記第1利用者情報とともに前記第2利用者に転送され;前記第2利用者から前記金融機関に前記第1利用者情報が提示され;前記金融機関は前記第1利用者情報に基づく前記第2暗号鍵を生成して前記第2利用者に転送し;前記第2利用者は前記転送された第2暗号鍵を用いて前記ディジタルキャッシュ管理プログラムにより前記再暗号化ディジタルキャッシュデータを復号する、ディジタルキャッシュ管理システム。
- 17A digital cache management system for utilizing the encrypted digital cache supplied by a financial institution to a first user:the digital cache management system uses a public key and a private key;the first user. Presents the first public key to the financial institution;the financial institution encrypts the digital cache data with the first public key and supplies it to the first user;the first user outputs the digital cache data. Decryption using the first dedicated key;the second user presents the second public key to the first user;the first user presents the decrypted digital cache data with the second public key. A digital cache management system that encrypts and transfers to a second user;the second user decrypts the digital cache data using a second dedicated key. 暗号化されて金融機関から第1利用者に供給されるディジタルキャッシュを利用するためのディジタルキャッシュ管理システムであって:該ディジタルキャッシュ管理システムでは公開鍵及び専用鍵が利用され;前記第1利用者は前記金融機関に第1公開鍵を提示し;前記金融機関は前記第1公開鍵でディジタルキャッシュデータを暗号化して前記第1利用者に供給し;前記第1利用者は前記ディジタルキャッシュデータを第1専用鍵を用いて復号し;前記第2利用者は前記第1利用者に第2公開鍵を提示し;前記第1利用者は復号化された前記ディジタルキャッシュデータを第2公開鍵で暗号化して第2利用者に転送し;前記第2利用者は前記ディジタルキャッシュデータを第2専用鍵を用いて復号する、ディジタルキャッシュ管理システム。
Independent claims6
282 paragraphs, as filed
The present invention relates to a system for managing copyright in the use, storage, copying, processing, and transfer of digital data, and is particularly considered to be used for a multimedia system.
In today's information age, database systems are becoming widespread in which various types of data stored independently by each computer are used by connecting each computer via a communication line. The information handled so far in this database system is coded information with a small amount of information that can be processed by a classical computer and monochrome binary data such as facsimile information at best, natural images and moving images. It was not possible to handle data with an extremely large amount of information such as.
By the way, with the development of digital processing technology for various electric signals, the development of digital processing technology for image signals other than binary data, which have been conventionally treated only as analog signals, is being promoted. Since the digitization of this image signal makes it possible for a computer to handle an image signal such as a television signal, a "multimedia system" that simultaneously handles various data handled by the computer and image data obtained by digitizing the image signal. Is attracting attention as a future technology.
Since image data has an overwhelmingly large amount of information as compared with character data and voice data, it is difficult to store, transfer, or perform various processes in a computer as it is. Therefore, it is conceivable to compress / decompress these image data, and several standards for image data compression / decompression have been created. Among them, JPEG (Joint Photographic image coding Experts Group) standard for still images, H.261 standard for television conferences, and MPEG1 (Moving Picture image coding Experts Group 1) standard for image storage have been used as common standards. And the MPEG2 standard corresponding to high-definition television broadcasting was created from the current television broadcasting. These technologies have enabled real-time processing of digital video data.
Since the quality of analog data, which has been widely used in the past, deteriorates every time it is stored, copied, processed, or transferred, the copyright processing caused by these operations has not become a major problem. However, since the quality of digital data does not deteriorate even if it is repeatedly stored, copied, processed, and transferred, the copyright processing caused by these operations is a big problem. Until now, there has been no accurate method for copyright processing of digital data, and it is processed by the Copyright Law or by contract, and the Copyright Law also institutionalizes compensation for digital recording equipment. It's just that.
The usage of the database is not only to refer to the contents, but also to make effective use of the obtained data by storing, copying, and processing, and the processed data can be used online via a communication line or as an appropriate storage medium. You can even transfer it online to someone else, or even transfer it to a database and register it as new data. In the conventional database system, only character data was targeted, but in a multimedia system, in addition to data such as characters that have been stored in a database so far, audio data and image data, which are originally analog data, are digital. It is converted into a database.
In such a situation, how to handle the copyright of the data stored in the database becomes a big problem, but so far, the copyright management means for that purpose, especially the secondary use such as copying, processing, and transfer. There is no complete rights management measure for. The present inventors use Japanese Patent Application Laid-Open No. 6-46419 and Japanese Patent Application Laid-Open No. 6-141004 to manage copyright by obtaining a license key from a key management center through a public telecommunication telephone line. The issue proposed a device for that purpose.
In addition, in Japanese Patent Application No. 6-64889, by further developing these above-mentioned prior inventions, the primary display (including audio conversion), storage, etc. of digital data in a database system including real-time transmission of digital video We proposed a copyright management method for secondary use such as use and copying, processing, and transfer.
In order to manage the copyright, the database copyright management system of this prior application is a program for managing the copyright, copyright information, or copyright management, in addition to the usage permission key corresponding to the applied usage pattern. Use any one or more of the messages.
The copyright management message is displayed on the screen when an attempt is made to use the copyright management message contrary to the application or permission content, and a caution or warning is given to the user, and the copyright management program is used contrary to the application or permission content. Monitor and manage so that there is no such thing.
The copyright management program, copyright information, and copyright management message are supplied in their entirety with the license key, in whole with the data, and partly with the license key, and partly in the data. May be supplied with. Data, license key, copyright management message, copyright information and copyright management program are sent in encrypted form, but if the encryption is broken at the time of use, they are sent in encrypted state and displayed. There are three cases: when the encryption is broken only when it is decrypted, and in other cases it is in the encrypted state, and when it is not encrypted at all .
<p>(Outline of the Invention) In the present application, a data copyright management system that embodies the data copyright management method proposed in the above-mentioned Japanese Patent Application No. 6-64889, which is a prior application, is provided.</p>
<p>In the present invention, the data copyright management system is composed of a database for storing original data, a key management center for managing encryption keys, a copyright management center for managing data copyrights, and a communication network connecting these to each other. The data supplied to the user from the database is encrypted and distributed, and the user decrypts and uses the encrypted data using the encryption key obtained from the key management center or the copyright management center. There are two methods for supplying data to the user, one is to supply the encrypted data in one direction by broadcasting or the like, and the other is to supply the encrypted data in both directions according to the user's request.</p><p>As the encryption key system used for data encryption, a private key system, a public key system, or a system combining a private key and a public key is adopted, and a copyright management program for managing data copyright is adopted.</p><p>When the user stores, copies or transfers data, the key may be supplied from the key management center or the copyright management center, or may be generated by the copyright management program.</p><p>The present invention is also applicable to a data copyright management system in which not only a single data but also a plurality of data supplied from a single database or a plurality of data supplied from a plurality of databases are used. .. We also propose a device used by the user to manage data copyrights.</p>
(Example) Hereinafter, the present invention will be described, but first, a general description of the encryption technique will be given. Cryptography includes a secret-key cryptosystem and a public-key cryptosystem. The private key encryption method is an encryption method that uses the same encryption key for encryption and decryption, and while the time required for encryption and decryption is short, the private key is discovered and the encryption is decrypted (Cryptanalize). There is. On the other hand, in public key cryptography, the encryption key is open to the public as a public-key, the decryption key is not open to the public, and the encryption key is the public key. The key for decryption is called a private-key. To use this encryption method, the sender of information encrypts with the public key of the receiver of the cipher, and the receiver of the information decrypts with a private key that is not publicly available. Although it is an encryption method and takes a long time to encrypt and decrypt, it is almost impossible to find a dedicated key and it is very difficult to decrypt the encryption.
In cryptography, the case where plaintext M is encrypted using encryption key K to obtain cryptogram C is expressed as C = E (K, M), and ciphertext C is the encryption key. The case of decoding using K to obtain the plaintext M is expressed as M = D (K, C). The cryptosystem used in the present invention is a secret-key system in which the same private key Ks is used for encryption and decryption, and a public key Kb is used for cryptography. Then, a public-key system is adopted in which a private-key Kv is used to decrypt the cryptography.
[Example 1] FIG. 1 shows the first embodiment of the database copyright management system according to the present invention. In the first embodiment, the private key method is adopted as the encryption key method. In the embodiment shown in this figure, 1 is a database in which text data, computer graphics screen or computer program binary data, digital audio data, and digital video data are stored in an encrypted state, and 2 is communication / communication. Artificial satellites such as broadcasting satellites, 3 is a data recording device such as a CD-ROM or flexible disk, 8 is a communication network such as a public line provided by a communication company or a CATV line provided by a cable television company, 4 is 1 Next user terminal device. In addition, 9 is a key management center that manages private keys, and 10 is a copyright management center that manages database copyrights.
5, 6 and 7 are secondary user terminal devices, tertiary user terminal devices and nth user terminal devices, respectively, and 11, 12 and 13 are secondary disks which are storage media such as flexible disks or CD-ROMs, respectively. It is a tertiary disc and an nth disc. Note that this n is an arbitrary integer, and when n is larger than 4, it corresponds between the third-order user terminal device 6 and the n-th-order user terminal device 7, and between the third-order disk 12 and the n-th-order disk 13. The user terminal device and the disk to be used are arranged.
Of these, the database 1, the key management center 9, the copyright management center 10, the primary user terminal device 4, the secondary user terminal device 5, the tertiary user terminal device 6, and the nth user terminal device 7 are connected to the communication network 8. Has been done. In this figure, the route shown by the broken line is the route of the encrypted data, the route shown by the solid line is the route of the request from each user terminal device, and the route shown by the alternate long and short dash line is each. This is the route to which the private key is transferred together with the permission information corresponding to the usage pattern from the database. In addition, each user who uses this system is registered in the database organization in advance. In addition, database organization use software is provided to the user at the time of this registration. This database organization use software includes a program for operating a copyright management program in addition to ordinary communication software such as a data communication protocol.
Text data stored in database 1 or data recording device 3, binary data that is a computer graphics screen or computer program, digital audio data, and original data M0 that is digital video data are communication network 8, artificial satellite 2, or storage medium. It is unidirectionally supplied to the primary user terminal device 4 via 3, but at this time, it is encrypted using the first private key Ks1. Cm0ks1 = E (Ks1, M0) Even if the data is provided free of charge, such as with advertisements, encryption is required for copyright protection.
In the previously mentioned prior application, Japanese Patent Application No. 6-64889, there are storage, processing, copying, and transfer in addition to the most basic display, and the license key is the use of these. Corresponding to one or more of the forms are provided and their management is shown to be performed by a rights management program. It is also stated that when data is stored, copied, or transferred, the data is re-encrypted by a copyright management program. In other words, copyrighted data is distributed in an encrypted state, and is only publicized when it is displayed or displayed for processing on a user terminal device that has a copyright processing function. is there.
In this embodiment, the matters described in these prior applications are used. The primary user who wishes to use the supplied encrypted data Cm0ks1 for the primary use the primary user terminal device 4 for the key management center 9 and gives the original data name or the original data number via the communication network 8. By specifying, the primary usage application for the encrypted original data Cm0ks1 is made, but at this time, the information Iu1 about the primary user is presented to the key management center 9. The key management center 9 that received the primary usage application using the primary user terminal device 4 is for decrypting the encryption original data Cm0ks1 that the primary user obtained from the database 1 together with the copyright management program P. The first private key Ks1 and the decrypted original data M0 or the second private key Ks2 for re-encrypting the processed data M1 obtained by processing the original data are used in the primary user terminal device 4 via the communication network 8. Transfer to.
In the primary user terminal device 4 that has received the first private key Ks1 that is the decryption key and the second private key Ks2 that is the encryption / decryption key, the first private key Ks1 is first used by the copyright management program P. The encrypted original data Cm0ks1 is decrypted using M0 = D (Ks1, Cm0ks1), and the decrypted original data M0 is used as it is or as processed data M1.
When the data M, which is the original data M0 or the processed data M1, is stored inside the primary user terminal device 4, that is, in the memory or the built-in hard disk drive, the data can be used only by the primary user. However, if the data M is copied to an external storage medium 11 such as a flexible disk, or transferred to the secondary user terminal device 5 via the communication network 8, there will be a copyright problem due to secondary use. ..
Also, if the original data M0 obtained by the primary user is copied as it is and supplied to the secondary user, the original data M0 has not been modified in any way, so the copyright of the primary user is applied to the data M0. Does not occur. However, if processing is performed based on the data M0 obtained by the primary user, or if new data M1 is created by combining with other data, the copyright of the primary user is applied to the data M1. (Secondary exploitation right) occurs. Similarly, when the secondary user performs processing based on the original data M0 or processing data M1 obtained from the primary user, or when new data M2 is created by using means such as combining with other data. , Similarly, the copyright of the secondary user is generated.
In order to deal with this copyright problem, in this embodiment, when the data M is stored, copied, or transferred, the copyright management program P encrypts the data M using the second private key Ks2, and thereafter 1 In the next user terminal device 4, the data M is decrypted and encrypted using the second private key Ks2. Cmks2 = E (Ks2, M) M = D (Ks2, Cmks2) In principle, the primary user can freely display and process the data and obtain the processed data, but in that case, it depends on the copyright management program. A limit can be set on the number of times.
When the data M is copied to the external storage medium 11 and when the data is transferred via the communication network 8, the first private key Ks1 and the second private key Ks2 in the primary user terminal device 4 are transferred by the copyright management program P. Will be discarded. Therefore, when the primary user wants to use the data M again, it is necessary to apply to the key management center 9 and receive the reissue of the second private key Ks2. The reissue of the second private key Ks2 means that the data M is copied to the external storage medium 11 or transferred to the secondary user terminal device 5 via the communication network 8 for secondary use. Since it means that it has been lost, this is registered from the key management center 9 to the copyright management center 10 and can be used for secondary use thereafter.
The movement of data M from the primary user terminal device 4 to the secondary user terminal device 5 is performed by the external storage medium 11 or the communication network 8, and is copied to the external storage medium 11 or moved via the communication network 8. When this is done, the data M is encrypted using the second private key Ks2.
Although the first private key Ks1 and the second private key Ks2 in the primary user terminal device 4 are discarded when the data M is copied to the external storage medium 11 and when the data M is transferred via the communication network 8. At this time, the unencrypted primary user information Iu1 is added to the encrypted data Cmks2 stored in the primary user terminal device 4, and when transferring the encrypted data Cmks2 to the secondary user, 1 Next user information Iu1 is also transferred.
The secondary user who wishes to use the encrypted data Cmks2 copied or transferred from the primary user for the secondary use uses the secondary user terminal device 5 to contact the copyright management center 10 via the communication network 8. Specify the original data name or original data number and present the secondary user information Iu2 to apply for secondary use, but at that time it is added to the encrypted data Cmks2 to clarify the relationship with the primary user. It also presents the unencrypted primary user information Iu1. The copyright management center 10 confirms that the primary user has been reissued the second private key Ks2 for secondary use of the data based on the presented primary user information Iu1, and decrypts the data. The second private key Ks2, which is the key, and the third private key Ks3, which is the encryption / decryption key, are transferred to the secondary user terminal device 5 via the communication network 8. In the secondary user terminal device 5 that has received the second private key Ks2 and the third private key Ks3, the encrypted data Cmks2 is decrypted by the copyright management program P using the second private key Ks2, and M = D (Ks2, Ks2, Cmks2) Secondary use of display or processing is performed.
In this embodiment, the primary usage application is processed by the key management center 9, and the secondary usage application is processed by the copyright management center 10. In addition, the data M supplied by the primary user is encrypted using the first private key Ks1, but the data M supplied by the secondary user is encrypted using the second private key Ks2. .. On the other hand, the first private key Ks1 and the second private key Ks2 are transferred from the key management center 9 to the primary user as encryption keys. Therefore, if the secondary user pretends to be the primary user and makes a primary usage application to the key management center 9, the first private key Ks1 is used as the decryption key and the first encryption / decryption key is used. 2 The private key Ks2 is transferred. However, the encrypted data Cmks2 cannot be decrypted using the first private key Ks1 transferred as the decryption key. Therefore, it is impossible to make a false application for the use of data, and as a result, not only the original copyright of the data but also the copyright of the primary user for the data is protected.
When storage, copying, and transfer, which are usage forms other than the display and processing of data M, are performed in the secondary user terminal device 5, the data M is encrypted by the copyright management program P using the third private key Ks3. After that, the data is decrypted and encrypted using the third private key Ks3. Cmks3 = E (Ks3, M) M = D (Ks3, Cmks3) In principle, the secondary user can freely display and process and obtain processing data M2, but in that case, the copyright management program P A limit can be set on the number of times.
When the data M is copied to the external storage medium 12 and when the data is transferred via the communication network 8, the second private key Ks2 and the third private key Ks3 in the secondary user terminal device 5 are transferred by the copyright management program P. Will be discarded. Therefore, when the secondary user uses the data M again, it is necessary to apply to the copyright management center 10 and receive the reissue of the third private key Ks3. The reissue of the third private key Ks3 means that the data M is copied to the external storage medium 12 or transferred to the tertiary user terminal device 6 via the communication network 8 for secondary use. Since it means that it has been damaged, this is registered in the copyright management center 10 and can be used later.
The movement of data M from the secondary user terminal device 5 to the tertiary user terminal device 6 is performed by the external storage medium 12 or the communication network 8, and is copied to the external storage medium 12 or moved via the communication network 8. When this is done, the data M is encrypted using the third private key Ks3.
The second secret key Ks2 and the third secret in the secondary user terminal device 5 when the data M is copied to the external storage medium 12 and when the data M is transferred to the tertiary user terminal device 6 via the communication network 8. The key Ks3 is discarded, but at this time, the encrypted data Cmks3 stored in the secondary user terminal device 5 is added with the unencrypted secondary user information Iu2. When transferring to the next user, the secondary user information Iu2 is also transferred. In this case, each user information is added to the data when all the user information is added to the data each time it is copied or transferred, and the history of being rewritten to the latest one each time is stored in the copyright management center. May occur.
A tertiary user who wishes to use the encrypted data Cmks3 copied or transferred from the secondary user for the tertiary use uses the tertiary user terminal device 6 to contact the copyright management center 10 via the communication network 8. Specify the original data name or original data number and present the tertiary user information Iu3 to apply for the tertiary use, but at that time, it is added to the encrypted data Cmks3 to clarify the relationship with the secondary user. It also presents the unencrypted secondary user information Iu2. The copyright management center 10 confirms that the secondary user has undergone the preparatory procedure for the tertiary use of the data based on the presented secondary user information Iu2, that is, the reissue of the third private key Ks3. Then, the third private key Ks3, which is the decryption key, and the fourth private key Ks4, which is the encryption / decryption key, are transferred to the tertiary user terminal device 6 via the communication network 8. In the tertiary user terminal device 6 that has received the third private key Ks3 and the fourth private key Ks4, the encrypted data Cmks3 is decrypted by the copyright management program P using the third private key Ks3, and M = D (Ks3, Ks3, Cmks3) The tertiary use of display or processing is performed.
In this embodiment, the data M supplied by the primary user is encrypted using the first private key Ks1 and the data M supplied by the secondary user is encrypted using the second private key Ks2. However, the data M supplied by the tertiary user is encrypted using the third private key Ks3. Therefore, when the primary usage application is made to the key management center 9 by pretending that the tertiary user is the primary user, the first private key Ks1 is used as the decryption key and the encryption / decryption key is used as the first encryption / decryption key. 2 The private key Ks2 is transferred. However, the encrypted data Cmks3 cannot be decrypted using the first private key Ks1 transferred as the decryption key. In addition, when a secondary usage application is made to the copyright management center 9 by pretending that the tertiary user is a secondary user, the second private key Ks2 is used as the decryption key as the encryption / decryption key. The third private key Ks3 is transferred. However, the encrypted Cmks3 cannot be decrypted using the second private key Ks2 transferred as the decryption key. Therefore, it is impossible to make a false application for the use of data, and as a result, not only the original copyright of the data but also the copyright of the primary user and the copyright of the secondary user regarding the data are protected. Below, the same procedure applies to the fourth and subsequent uses.
The database 1, key management center 9, and copyright management center 10 in the above-described embodiment are installed separately, but they do not necessarily have to be separate, and all or appropriate two of them are integrated. It is also possible to install it in. Further, the application for reissuance of the secondary encryption key from the primary user may be made to the copyright management center 10 instead of the key management center 9 as in the embodiment.
[Example 2] Next, a second embodiment will be described. Most of the configurations of this embodiment are the same as those of the first embodiment, but with a copyright management program and, in some cases, a first private key. The second private key is encrypted and supplied. In this embodiment as well as in the first embodiment, the original data is encrypted from a single database and supplied in one direction, and the user selects and uses the necessary original data from the supplied original data. Since the system configuration used in the second embodiment is not different from the system configuration of the first embodiment shown in FIG. 1, the description of the system configuration will be omitted.
In this embodiment, the original data M0 stored in the database 1 is unidirectionally supplied to the primary user terminal device 4 via the artificial satellite 2, the storage medium 3, or the communication network 8. 1 Encrypted using the private key Ks1. Cm0ks1 = E (Ks1, M0)
The primary user who wishes to use the supplied encrypted data Cm0ks1 for the primary use the primary user terminal device 4 for the key management center 9 and gives the original data name or the original data number via the communication network 8. By specifying, the primary usage application for the encrypted original data Cm0ks1 is made, but at this time, the primary user information Iu1 is presented to the key management center 9.
The key management center 9 that receives the primary usage application of the encrypted original data Cm0ks1 uses the primary user information Iu1 to generate a private key Ksu1 dedicated to the primary user and transfers it to the copyright management center 10.
The copyright management center 10 that received the private key Ksu1 dedicated to the primary user encrypts the copyright management program P using this private key Ksu1 dedicated to the primary user, and Cpksu1 = E (Ksu1, P) encrypted copyright. Transfer the management program Cpksu1 to the key management center 9. The encrypted copyright management program Cpksu1 generated in this way is unique to the primary user. In addition, the key management center 9 uses the encryption copyright management program Cpksu1 received from the copyright management center 10 as well as the first private key Ks1 which is the decryption key and the second private key Ks2 which is the decryption / encryption key in the communication network. Transfer to the primary user terminal device 4 via 8.
In the primary user terminal device 4 that received the encrypted copyright management program Cpksu1, the first private key Ks1, and the second private key Ks2, the database organization software S distributed in advance at the beginning becomes the primary user information Iu1. Based on this, the primary user-only private key Ksu1 is generated, and Ksu1 = S (Iu1) The generated primary user-only private key Ksu1 is used to decrypt the encryption copyright management program Cpsu1, and P = D (Ksu1, Cpsu1). ) The encrypted original data Cm0ks1 is decrypted using the first private key Ks1 using the decrypted copyright management program P, and M0 = D (Ks1, Cm0ks1) The decrypted original data M0 is used as it is or processed data. Use as M1.
When the original data M0 or the processed data M1 is stored, copied, or transferred, the data M is encrypted by the copyright management program P using the second private key Ks2, and thereafter in the primary user terminal device 4. Data M is decrypted and encrypted using the second private key Ks2. Cmks2 = E (Ks2, M) M = D (Ks2, Cmks2)
When the data M is copied to the external storage medium 11 and when the data is transferred via the communication network 8, the first private key Ks1 and the second private key Ks2 in the primary user terminal device 4 are transferred by the copyright management program P. Will be discarded. Therefore, when the primary user wants to use the data M again, it is necessary to apply to the key management center 9 and receive the reissue of the second private key Ks2. The reissue of the second private key Ks2 means that the data M is copied to the external storage medium 11 or transferred to the secondary user terminal device 5 via the communication network 8 for secondary use. Since it means that it has been lost, this is registered from the key management center 9 to the copyright management center 10 and can be used for secondary use thereafter.
The movement of the data M from the primary user terminal device 4 to the secondary user terminal device 5 is performed by the external storage medium 11 or the communication network 8. When the data M is copied to the external storage medium 11 or transferred via the communication network 8, the data M is encrypted using the second private key Ks2.
Although the first private key Ks1 and the second private key Ks2 in the primary user terminal device 4 are discarded when the data M is copied to the external storage medium 11 and when the data M is transferred via the communication network 8. At this time, the unencrypted information Iu1 about the primary user is added to the encrypted data Cmks2 stored in the primary user terminal device 4. Therefore, when the encrypted data Cmks2 is transferred to the secondary user, the primary user information Iu1 is also transferred.
The secondary user who wishes to use the encrypted data Cmks2 copied or transferred from the primary user for the secondary use uses the secondary user terminal device 5 to contact the copyright management center 10 via the communication network 8. Specify the original data name or original data number and present the secondary user information Iu2 to apply for secondary use, but at that time it is added to the encrypted data Cmks2 to clarify the relationship with the primary user. It also presents the unencrypted primary user information Iu1. The copyright management center 10 confirms that the primary user has been reissued the second private key Ks2 for secondary use of the data based on the presented primary user information Iu1, and is presented. Generates a private key Ksu2 dedicated to the secondary user based on the secondary user information Iu2.
The copyright management center 10 encrypts the copyright management program P using this secondary user-only private key Ksu2, and Cpksu2 = E (Ksu2, P) encryption Copyright management program Cpksu2, the second secret that is the decryption key. The key Ks2 and the third private key Ks3, which is the encryption / decryption key, are transferred to the secondary user terminal device 5 via the communication network 8. Information about the primary user Iu1 may be added to this encrypted copyright management program Cpksu2.
In the secondary user terminal device 5 that received the second private key Ks2 and the third private key Ks3, the database organization use software generates the secondary user-only private key Ksu2 based on the secondary user information Iu2, and Ksu2 = S ( Iu2) Decrypt the encrypted copyright management program Cpsu2 using the generated secondary user-only private key Ksu2, and use the decrypted copyright management program P with P = D (Ksu2, Cpsu2) for the second secret. The encrypted original data Cmks2 is decrypted using the key Ks2, and the decrypted data M = D (Ks2, Cmks2) is used as it is or after being processed.
In this way, a data copyright management system is created by generating a user-only encryption key based on the user information of the user who applied for use and encrypting the copyright management program using the generated user-only encryption key. Is more secure. Further, if each private key supplied to the user at this time is also encrypted using the user-dedicated encryption key, the security of the data copyright management system can be further enhanced.
[Example 3] Further, in the system shown in FIG. 1, the copyright problem that occurs when the data M is copied to the external storage medium 11 or when the data M is transferred via the communication network 8 is dealt with. As yet another method for doing so, the primary usage application made by the user of the primary user terminal 4 is limited to display permission, storage permission, and processing permission, and other usage applications, that is, copy permission and transfer permission are obtained. When the data M is copied to the external storage medium 11 and when the data is transferred to the secondary user terminal device 5 via the communication network 8, the application for the copy permission and the transfer permission should be made separately. The first private key Ks1 and the second private key Ks2 in the primary user terminal device 4 can also be discarded. In this way, the copy or transfer of the data M can be more reliably grasped by the copyright management center 10.
[Example 4] FIG. 2 shows the configuration of Example 4 of the data copyright management system according to the present invention. In the system shown in FIG. 1, the encrypted data is unidirectionally supplied via the satellite 2, the recording medium 3, or the communication network 8, but in the second embodiment, in response to the request from the primary user 4. Encrypted data is supplied bidirectionally. Further, in this embodiment, a public key system is adopted as the encryption key system. Needless to say, Example 2 can also be applied to the case where satellite broadcasting, terrestrial broadcasting, CATV broadcasting or a recording medium that does not need to be encrypted free of charge, such as with an advertisement, is used as a data supply means other than the database. Is.
Similar to the system shown in Figure 1, in the system shown in this figure, 1 is the database, 4 is the primary user terminal device, 5 is the secondary user terminal device, 6 is the tertiary user terminal device, and 7 is n. Next user terminal device. In addition, 14 is a secondary copyright management center, 15 is a tertiary copyright management center, 16 is an nth copyright management center, and 8 is a public line provided by a telecommunications carrier or a CATV line provided by a cable television operator. Etc. is a communication network.
Of these, database 1, primary user terminal device 4, secondary user terminal device 5, tertiary user terminal device 6, nth user terminal device 7, secondary copyright management center 14, tertiary copyright management center 15 The nth copyright management center 16 is connected to the communication network 8 and can be connected to each other. In this figure, the route shown by the broken line is the route of the encrypted data, the route shown by the solid line is the route of the request from each user terminal device, and the route shown by the alternate long and short dash line is each. It is a route to which the encryption key is transferred together with the permission information corresponding to the usage pattern from the database, and the route indicated by the alternate long and short dash line is the copyright from the database or each copyright management center database to the next copyright management center database. This is the route through which information is transferred. In addition, each user who uses this system is registered in the database organization in advance. In addition, database organization use software is provided to the user at the time of this registration. This database organization use software includes a program for decrypting an encrypted copyright management program in addition to ordinary communication software such as a data communication protocol.
When using database 1, the primary user uses the primary user authentication data Au1, the first public key Kb1, and the first private key Kv1, the second public key Kb2, and the second public key Kb2 corresponding to the first public key Kb1. Prepare the corresponding second dedicated key Kv2 and access the database 1 via the communication network 8 using the primary user terminal device 4.
Database 1 that received the transfer of the primary user authentication data Au1, the first public key Kb1 and the second public key Kb2 from the primary user confirmed the primary user authentication data Au1 and confirmed the primary user authentication data Au1. Is transferred to the secondary copyright management center 14 as the primary user information Iu1.
On the other hand, database 1 prepares two private keys, that is, the first private key Ks1 and the second private key Ks2. The two private keys may be prepared by using the key center 9 of the first embodiment shown in FIG. Of the prepared first private key Ks1 and second private key Ks2, the second private key Ks2 is also transferred to the copyright management center 14 in advance.
As a result of these transfers, the primary user information Iu1, the original copyright information Ic, and the second private key Ks2 are stored in the copyright management center 14. Among these, the original copyright information Ic is used for distribution of copyright usage fees.
When the primary user who wishes to use the data accesses the database 1 using the primary user terminal device 4, the data menu is transferred. At this time, the charge information may be displayed together with the data menu.
When the data menu is transferred, the primary user searches the data menu and selects data M. At this time, the original copyright information Ic of the selected data M is transferred to the copyright management center 14.
The original data M0 is read from database 1 in response to the request of the primary user. The read original data M0 is encrypted with the first private key Ks1. Cm0ks1 = E (Ks1, M0) This encrypted data Cm0ks1 is attached with the unencrypted original copyright holder information Ic. Also, the first private key Ks1 is encrypted with the first public key Kb1 and the second private key Ks2 is encrypted with the second public key Kb2. Cks1kb1 = E (Kb1, Ks1) Cks2kb2 = E (Kb2, Ks2) The copyright management program P is also encrypted with the second private key Ks2, but Cpks2 = E (Ks2, P) copyright management program P The encryption of is not required to be encrypted with the second private key Ks2, but can be encrypted with another suitable encryption key. The encryption source data Cm0ks1, the encryption copyright management program Cpks2, and the two encryption private keys Cks1kb1 and Cks2kb2 are transferred to the primary user terminal device 4 via the communication network 8. At this time, billing will be made if necessary. The encrypted copyright management program Cpks2 is not supplied from the database 1, but can be built in, for example, a ROM in the user terminal device 4.
The primary user who receives the encryption original data Cm0ks1, 2 encryption private keys Cks1kb1, Cks2kb2 and the encryption copyright management program Cpks2 from database 1 supports the first public key Kb1 using the database organization use software. Encrypt using the 1st private key Kv1 to decrypt the 1st private key Cks1kb1 and encrypt using the 2nd private key Kv2 corresponding to Ks1 = D (Kv1, Cks1kb1) 2nd public key Kb2 2nd private key Decrypt Cks2kb2. Ks2 = D (Kv2, Cks2kb2) Furthermore, the encrypted copyright management program Cpks2 is decrypted using the decrypted second private key Ks2. P = D (Ks2, Cpks2)
Finally, the encrypted data Cm0ks1 is decrypted using the first private key Ks1 decrypted using the decrypted copyright management program P, and the original data decrypted by M0 = D (Ks1, Cm0ks1). Use M0 as it is or as processing data M1. As explained earlier, the first dedicated key Kv1 and the second dedicated key Kv2 are encryption keys prepared by the primary user and not disclosed to others, so even if a third party obtains the encrypted data. It is impossible to decrypt and use the encrypted data.
After that, when saving, copying or transferring the original data M0 or the processed data M1 data M, encryption and decryption are performed using the second private key Ks2. Cmks2 = E (Ks2, M) M = D (Ks2, Cmks2) The decrypted second private key Ks2 is the encryption for encrypting / decrypting data when storing, copying or transferring data thereafter. Used as a key. The primary user terminal device 4 is provided with the original copyright information Ic together with the first dedicated key Kv1 and the second dedicated key Kv2, the first private key Ks1 and the second private key Ks2, the data M, and the copyright management program P. And when the primary user processes the data, the primary user information and the copyright information Ic1 which is the processing date and time are also stored. It is safe to attach this copyright information Ic1 to the data as a copyright information label and also attach it with a digital signature. The encrypted data Cmks2 is encrypted and distributed, and the copyright information label is a clue in order to obtain the second private key Ks2, which is the decryption key. Therefore, this copyright information label is removed from the encrypted data Cmks2. If this happens, the second private key Ks2 cannot be obtained.
When the encrypted data Cmks2 is stored in the primary user terminal device 4, the second private key Ks2 is stored in the device, but the encrypted data Cmks2 is stored in the primary user terminal device 4. If the data is copied to the storage medium 11 or transferred to the secondary user terminal device 5 via the communication network 8 without any reason, the primary user terminal device 4 cannot be used later. The private key Ks2 of 2 is discarded. In this case, a limit may be set on the number of copies / transfers so that the second private key Ks2 is not discarded when the number of copies / transfers is within the limit.
The primary user who intends to copy or transfer the data M to the external storage medium 11 via the communication network 8 prepares the second private key Ks2 for copying or transferring, and transfers the data M to the second private key Ks2. Encrypt using. Cmks2 = E (Ks2, M) Unencrypted original copyright information Ic and primary user copyright information Ic1 are added to this encrypted data Cmks2.
The secondary user uses the authentication data Au2 for authenticating the secondary user in the same way as the primary user before using the database, the third public key Kb3, and the third private key Kv3 corresponding to the third public key Kb3. Prepare a fourth private key Kv4 corresponding to the fourth public key Kb4 and the fourth public key Kb4.
The secondary user who desires the secondary use of the encrypted data Cmks2 that has been copied or transferred uses the secondary user terminal device 5 to send the original data to the secondary copyright management center 14 via the communication network 8. When applying for secondary usage by specifying the name or original data number, at that time, in addition to the secondary user authentication data Au2, original copyright information Ic and primary user copyright information Ic1, the third public key Kb3 And the fourth public key Kb4 are also transferred.
The secondary copyright management center 14 that received the secondary usage application from the secondary user confirms the authentication data Au2 of the secondary user, and the confirmed secondary user authentication data Au2 is the tertiary copyright as the secondary user information. Transferred to the rights management center 15. In addition, when the secondary copyright information Ic1 of the primary user is transferred, the secondary copyright information Ic1 is inquired and confirmed to the secondary copyright management center 14, and the confirmed secondary copyright information Ic1 Is transferred to the tertiary copyright management center 15.
The secondary copyright management center 14 prepares a third private key Ks3. The third private key Ks3 may be prepared by using the key center 9 shown in the first embodiment. The prepared third private key Ks3 is transferred to and stored in the tertiary copyright management center 15.
As a result of these transfers, the primary user copyright information Ic1, the primary user information I1, the original copyright information Ic, the secondary user information Iu2, and the third private key Ks3 are sent to the tertiary copyright management center 15. Is stored. Of these, the primary user copyright information Ic1 and the primary user information I1 are used for copyright usage fee distribution.
Similarly, in the nth copyright management center 16, (n-1) secondary copyright information of the next user Icn-1, primary user information I1, original copyright information Ic, nth user information In and The nth private key Ksn is stored.
The primary user information I1, the original copyright information Ic, and the second private key Ks2 are read from the secondary copyright management center 14. Of these, the original copyright information Ic is used for allocating copyright royalties. The read second private key Ks2 is encrypted using the secondary user's third public key Kb3, and the third private key Ks3 is also encrypted using the fourth public key Kb4. Cks2kb3 = E (Kb3, Ks2) Cks3kb4 = E (Kb4, Ks3) Also, the copyright management program P uses the third private key Ks3, and the third private key Ks3 uses the fourth public key Kb4. It will be encrypted. Cpks3 = E (Ks3, P) Cks3kb4 = E (Kb4, Ks3) Encryption copyright management program Cpks3 and encryption second private key Cks2kb3 and encryption third private key Cks3kb4 are secondary users via communication network 8. Transferred to terminal device 3. At this time, billing will be made if necessary.
The secondary user who receives the two encrypted private keys Cks2kb3 and Cks3kb4 and the encrypted copyright management program Cpks3 from the secondary copyright management center 14 uses the database usage software to use the third dedicated key Kv3. The encrypted second private key Cks2kb3 is decrypted using, and the encrypted third private key Cks3Kb4 is decrypted using the fourth private key Kv4 corresponding to the fourth public key Kb4. Ks2 = D (Kv3, Cks2kb3) Ks3 = D (Kv4, Cks3kb4) In addition, the encrypted copyright management program Cpks3 is decrypted using the decrypted third private key Ks3. P = D (Ks3, Cpks3) Next, the encrypted data Cmks2 is decrypted and used using the second private key Ks2 decrypted using the decrypted copyright management program P. M = D (Ks2, Cmks2)
As explained earlier, the 3rd dedicated key Kv3 and the 4th dedicated key Kv4 are encryption keys prepared only by the secondary user and not disclosed to others, so a third party obtains the encrypted data Cmks2. Even if it does, it is impossible to decrypt and use it.
In the embodiment described above, the database 1, secondary copyright management center 14, tertiary copyright management center 15, and nth copyright management center 16 are separately provided in order to avoid congestion of usage applications. However, if congestion of usage applications is not a problem, all or part of these can be combined.
[Example 5] Figure 3 shows the system configuration of Example 5. In this Example 5, the original data is encrypted from a single database and supplied in one direction, and the user Select and use the required data from the supplied original data. In this embodiment, the private key method is adopted as the encryption key method.
In this figure, 1 is a database in which text data, computer graphics screen or computer program binary data, digital audio data, and digital video data are stored in an encrypted state, and 2 is a communication / broadcasting satellite, etc. Artificial satellite, 3 is a data recording medium such as CD-ROM or flexible disk, 8 is a communication network such as a public line provided by a communication company or a CATV line provided by a cable television company, 4 is a primary user terminal device Is. In addition, 17 is a copyright management center that manages the copyright of data, and 5, 6 and 7 are a secondary user terminal device, a tertiary user terminal device and an nth user terminal device, respectively.
Of these, the database 1, the copyright management center 17, the primary user terminal device 4, the secondary user terminal device 5, the tertiary user terminal device 6 and the nth user terminal device 7 can be connected to each other by the communication network 8. ing.
Each user who uses this system needs to be registered in the database organization in advance. In addition, database usage software is provided to the user at the time of this registration. This software includes ordinary communication software programs such as data communication protocols. The software for using this database organization may be stored in a fixed disk in the user terminal device, but it can also be stored in a mask ROM, EPROM, EEPROM or the like built in the user terminal device.
Further, in this system, since the private key is generated on the user side, the private key generation algorithm is stored in the user terminal device, but since the private key generation algorithm itself is not necessarily secret, the database organization is notified. It may be built in the database organization use software supplied to the user when registering the use. If the original data is supplied free of charge, such as with advertisements, encryption may not be required, but even in that case, the copyright still exists, so procedures for using the copyright are necessary.
In this figure, the route shown by the broken line is the route of the encrypted data, the route shown by the solid line is the route of the request from each user terminal device, and the route shown by the alternate long and short dash line is the copyright. This is the route through which the encryption key is transferred from the rights management center.
The original data M0 stored in the database 1 or the data recording medium 3 is a primary user terminal device via a communication network 8 via a wired route, a broadcast radio wave via an artificial satellite 2 or the like, or via a recording medium 3. It is supplied to 4, but at this time it is encrypted using the first private key Ks1. Cm0ks1 = E (Ks1, M0)
As in the case of Examples 1 to 4, in order to protect the copyright of the original data Cm0ks1 supplied in encrypted form, it is shown in Japanese Patent Application No. 6-64889, which is a prior application by the present inventors. As described above, in the primary user terminal device 4, the original data M0 is encrypted using the second private key Ks2 when the storage, copying, and transfer, which are usage forms other than the display for display and processing, are performed. , Cm0ks2 = E (Ks2, M0) or later, the original data is encrypted / decrypted by the second private key Ks2.
The primary user who obtained the encrypted original data Cm0ks1 uses the primary user terminal device 4, specifies the original data name or the original data number, etc., and uses the encrypted original data Cm0ks1 for the primary use of the copyright management center. Apply for 17. The copyright management center 17 that receives the primary usage application of the encrypted original data Cm0ks1 from the primary user terminal device 4 transfers the copyright management program P to the primary user terminal device 4 together with the first private key Ks1. This copyright management program P includes a cryptographic program having a cryptographic algorithm, and this cryptographic program generates a private key and decrypts / encrypts data.
The primary user terminal device 4 that has received the first private key Ks1 and the copyright management program P decrypts the encrypted original data Cm0ks1 using the first private key Ks1 using the encryption program, and M0 = D (Ks1). , Cm0ks1) The decrypted original data M0 is used as it is or as processed data M1. In addition, the copyright management program P generates the second private key Ks2 based on the first private key Ks1. Ks2 = P (Ks1)
Copyright when the original data M0 or the data M which is the processed data M1 is stored in the primary user terminal device 4, copied to the recording medium 11, or transferred to the secondary user terminal device 5. It is encrypted by the management program P using the second private key Ks2. Cmks2 = E (Ks2, M)
The data Cmks2 encrypted by the second private key Ks2 is copied to the recording medium 11 or transferred to the secondary user terminal device 5 via the communication network 8 together with the original data name or the original data number.
The secondary user who obtained the encrypted data Cmks2 uses the secondary user terminal device 5 to specify the original data name or the original data number to perform the secondary use of the encrypted data Cmks2. Copyright management center 17 Apply to.
The copyright management center 17 that received the application for secondary use of the encrypted data Cmks2 searches for the first private key Ks1 from the original data name or the original data number, and uses the copyright management program P to search for the first private key Ks1 to the second secret. The key Ks2 is generated, and Ks2 = P (Ks1) The generated second private key Ks2 is supplied to the secondary user terminal device 5 together with the copyright management program P.
Upon receiving the second private key Ks2 and the copyright management program P, the secondary user terminal device 5 decrypts the data Cmks2 encrypted with the second private key Ks2 with the second private key Ks2 and M = D (Ks2, Cmks2) Use display or processing.
When the decrypted data M is stored in the secondary user terminal device 5, stored in the recording medium 12, or transferred to the tertiary user terminal device 6 via the communication network 8, the decrypted data M is stored in the secondary user terminal device 5. Data M is encrypted by the copyright management program P using the second private key Ks2.
Furthermore, the copyright management program P is made to generate the third private key Ks3 based on the second private key Ks2, and Ks3 = P (Ks2).
When the data M is stored in the secondary user terminal device 5, copied to the recording medium 12, or transferred to the tertiary user terminal device 6 via the communication network 8, the data M is It may be encrypted by the copyright management program P using the third private key Ks3. Cmks3 = E (Ks3, M)
[Example 6] Next, a sixth embodiment will be described. As in the fifth embodiment, the original data is encrypted and supplied in one direction from a single database, and the user needs from the supplied original data. Select and use the best one. The encryption key method adopted in this embodiment is a private key method, and the second private key is generated based on the primary user information and the first private key. Since the system configuration used in Example 6 is not different from the system configuration of Example 5 shown in FIG. 3, the description of the system configuration will be omitted.
In the sixth embodiment, the original data M0 stored in the database 1 is a first secret key Ks1 via a communication network 8 via a wired route, via an artificial satellite 2 or the like via broadcast radio waves, or via a recording medium 3. It is encrypted using and supplied to Cm0ks1 = E (Ks1, M0) primary user terminal device 4.
The primary user who obtained the encrypted original data Cm0ks1 applies to the copyright management center 17 for the primary use of the encrypted original data Cm0ks1 using the primary user terminal device 4, but at this time, the original data name or the original Specify the data number etc. and present the primary user information Iu1.
The copyright management center 17 that receives the primary usage application of the encrypted original data Cm0ks1 from the primary user supplies the first private key Ks1 and the copyright management program P to the primary user terminal device 4.
The copyright management program P includes a cryptographic program P having a cryptographic algorithm, and the private key generation and decryption / encryption are performed by this cryptographic program P.
In the primary user terminal device 4 that has received the first private key Ks1 and the copyright management program, the encryption program P decrypts the encrypted original data M0 using the first private key Ks1 and M0 = D (Ks1, Cm0ks1). The decrypted original data M0 is used as it is or as processed data M1. Further, the supplied copyright management program P generates the second private key Ks2 based on the primary user information Iu1 or the primary user information Iu1 and the first private key Ks1. Ks2 = P (Iu1) or Ks2 = P (Iu1 + Ks1) The generated second private key Ks2 is based on the primary user information Iu1, so if it does not have the correct primary user information Iu1, it should be generated. Is impossible. In addition, instead of the primary user information Iu1, the primary user data generated based on the primary user information Iu1 or the device number assigned to the primary user terminal device 4 can also be used.
When the original data M0 or the data M which is the processed data M1 is stored in the primary user terminal device 4, or copied to the recording medium 11, it is supplied to the secondary user terminal device 5 via the communication network 8. If so, the data M is encrypted by the copyright management program P using the second private key Ks2. Cmks2 = E (Ks2, M)
The data Cmks2 encrypted with the second private key Ks2 is copied to the recording medium 11 together with the original data name or the original data number and the primary user information Iu1, or is copied to the recording medium 11 or is copied to the secondary user terminal device 5 via the communication network 8. Is supplied to.
The secondary user who obtained the encrypted data Cmks2 applies for the secondary use of the data M to the copyright management center 17 by using the secondary user terminal device 5, but at this time, the original data name or the original data number. Etc. and present the primary user information Iu1.
The copyright management center 17 that receives the secondary use application of data M searches for the first private key Ks1 using the original data name or the original data number as a clue, and finds the primary user information Iu1, the first private key Ks1 or the primary user. The second private key Ks2 is generated based on the information Iu1 and the first private key Ks1, and the generated second private key Ks2 is provided to the secondary user terminal device 5 together with the copyright management program P.
The secondary user who received the second private key Ks2 and the copyright management program P uses the secondary user terminal device 5 to decrypt the encrypted data Cmks2 using the second private key Ks2 by the copyright management program P. To use. When M = D (Ks2, Cmks2) data M is stored in the secondary user terminal device 5, copied to the recording medium 11, and supplied to the tertiary user terminal device 6 via the communication network. The data is encrypted by the second private key Ks2.
If the copyright management program P generates the third private key Ks3 based on the second private key Ks2 and Ks3 = P (Ks2) data M is saved in the secondary user terminal device 5, it is recorded. When the data is copied to the medium 11 and supplied to the tertiary user terminal device 6 via the communication network, the data can be encrypted by the third private key Ks3.
In addition, when the secondary user makes a secondary usage application to the copyright management center 17, the secondary user information Iu2 is presented, and the third private key Ks3 is generated based on the presented secondary user information Iu2. You can also do it.
In the sixth embodiment, if the copyright management program P that generates the second private key Ks2 is set to be common to all database organizations, the primary user information Iu1 and the first private key Ks1 are not changed in any database organization. As long as the same original data is used, the same second private key Ks2 is generated.
[Example 7] Next, a seventh embodiment will be described. As in the fifth and sixth embodiments, the original data is encrypted from a single database and supplied in one direction, and the user is supplied. Select and use the required data from the original data. Further, in this embodiment, the second private key is generated based on the number of times the copyright management program is used and the first private key.
The encryption key method adopted in this embodiment is a private key method. Since the system configuration used in Example 7 is not different from the system configurations of Examples 5 and 6 shown in FIG. 3, the description of the system configuration will be omitted.
The original data M0 stored in the database 1 is encrypted using the first secret key Ks1 via the communication network 8 via a wired route, by broadcasting radio waves via an artificial satellite 2 or the like, or via a recording medium 3. Cm0ks1 = E (Ks1, M0) is converted and supplied to the primary user terminal device 4.
The primary user who obtained the encrypted original data Cm0ks1 uses the primary user terminal device 4 to specify the original data name or the original data number, etc., so that the primary use of the original data M0 is sent to the copyright management center 17. Apply.
The copyright management center 17 that has received the primary use application of the original data M0 transfers the first private key Ks1 and the copyright management program P to the primary user terminal device 4.
This copyright management program P includes a cryptographic program having a cryptographic algorithm, which generates a cryptographic key and decrypts / encrypts data. In addition, a counter is attached to the copyright management program P, and this counter counts the number of times N of the program P is used.
The primary user who receives the first private key Ks1 and the copyright management program P decrypts the encrypted original data Cm0ks1 using the copyright management program P using the first private key Ks1 and M0 = D (Ks1). , Cm0ks1) The decrypted original data M0 is used as it is or as processed data M1.
In this system, when the original data M0 or the data M which is the processed data M1 is stored in the primary user terminal device 4 or copied to the recording medium 11 in order to manage the copyright of the data, the communication network When transferred to the secondary user terminal device 5 via 8, it is encrypted by P using the second private key Ks1 in the copyright management program, but the second encryption key Ks2 used at this time is written. Generated based on the number of times the rights management program has been used N and the first private key Ks1. Ks2 = P (N + Ks1)
Since the second private key Ks2 generated in this way is based on the number of times N of the copyright management program P is used and the first private key Ks1, the data M is used with the latest second private key Ks2 each time it is used. It will be encrypted. Cmks2 = E (Ks2, M)
The data Cmks2 encrypted by the second private key Ks2 generated by the last use is copied to the recording medium 11 together with the original data name or the original data number and the counter data N1, or is secondary via the communication network 8. Transferred to the user terminal device 5.
The secondary user who has obtained the encrypted data Cmks2 presents the original data name or the original data number and the counter data N1 using the secondary user terminal device 5, and the secondary use of the encrypted data Cmks2 is performed by the copyright management center. Apply for 17.
The copyright management center 17 that received the secondary use application of the encrypted data Cmks2 searches for the first private key Ks1 from the presented original data name or original data number, and based on the counter data N1 and the first private key Ks1. The second private key Ks2 is generated, and the second private key Ks2 is supplied to the secondary user terminal device 5 via the communication network 8 together with the copyright management program P.
The secondary user who receives the second private key Ks2 and the copyright management program P decrypts the encrypted data Cmks2 using the copyright management program P using the second private key Ks2 and M = D (Ks2, Cmks2). ) The decrypted data M is used as it is or after being processed.
If the data M is stored in the secondary user terminal device 5, copied to the recording medium 11, or transferred to the tertiary user terminal device 6 via the communication network 8, the data M is written. It is encrypted by the second private key Ks2 by the rights management program P. Cmks2 = E (Ks2, M)
In this case, the copyright management program P can further generate the third private key Ks3 based on the number of times the copyright management program P is used in the secondary user terminal device 5 N2 and the private key Ks2. Ks3 = P (N2 + Ks2) In this case, when the data M is stored in the secondary user terminal device 5, when it is copied to the recording medium 11, it is transferred to the tertiary user 6 via the communication network 8. If so, the data M is encrypted by the copyright management program P with the third private key Ks3. Cmks3 = E (Ks3, M)
[Example 8] Fig. 4 shows the system configuration of Example 8 of the data copyright management system, and the original data supplied from a single database in this Example 8 is requested by the user. It is supplied bidirectionally accordingly. The encryption method adopted in this embodiment is a private key method, and a second private key is generated based on the first private key.
In this figure, 1 is a database, 4 is a primary user terminal device, 5 is a secondary user terminal device, 6 is a tertiary user terminal device, and 7 is an nth user terminal device. In addition, 18 is a copyright management center, and 8 is a communication network such as a public line provided by a telecommunications carrier or a CATV line provided by a cable television carrier.
Of these, the database 1, the copyright management center 18, the primary user terminal device 4, the secondary user terminal device 5, the tertiary user terminal device 6 and the nth user terminal device 7 can be connected to each other by the communication network 8. ing.
Each user who uses this system needs to be registered in the database organization in advance. In addition, database organization software is provided to the user at the time of this registration. This software includes ordinary communication software programs such as data communication protocols. This database organization software may be stored in a fixed disk in the user terminal device, but it can also be stored in a mask ROM, EPROM, EEPROM or the like built in the user terminal device.
Also, in this system, the private key generation algorithm is stored in the user terminal device to generate the private key on the user side, but since the private key generation algorithm itself is not necessarily secret, the use is registered in the database organization. It may be built into the database organization software provided to the user when doing so. In the case of original data supplied free of charge, such as with advertisements, encryption may not be required, but even in that case, the copyright exists, so procedures for using the copyright are necessary. ..
In this figure, the route shown by the broken line is the route of the encrypted data, the route shown by the solid line is the route of the request from each user terminal device, and the route shown by the alternate long and short dash line. Is a route to which the private key is transferred together with the usage permission information and the copyright management program corresponding to the usage pattern from each database.
In this figure, text data, graphics data or binary data, audio data, and video data are stored in the database 1 in an unencrypted state.
The primary user applies for the use of the original data M0 by specifying the original data name that he / she wants to use for the database 1 via the communication network 8 using the primary user terminal device 4.
Database 1, which received an application to use the original data M0 from the primary user terminal device 4, encrypts the original data M0 with the first private key Ks1, and Cm0ks1 = E (Ks1, M0) encrypted original data Cm0ks1 and the first. 1 Supply the copyright management program P together with the private key Ks1 to the primary user terminal device 4. This copyright management program P includes a cryptographic program having a cryptographic algorithm, and the cryptographic program P generates a private key and decrypts / encrypts data. If this encryption algorithm depends on the first private key Ks1, the copyright management program P can be unique to the original data M0.
The primary user terminal device 4 that receives the first private key Ks1 and the copyright management program P together with the original data Cm0ks1 encrypted using the first private key Ks1 uses the first private key Ks1 to encrypt the original data. Cm0ks1 is decoded, and M0 = D (Ks1, Cm0ks1) the decoded original data M0 is used as it is or as processed data M1. In addition, the copyright management program P generates a second private key Ks2 based on the first private key Ks1. Ks2 = P (Ks1)
When the decrypted original data or the processed data M is stored in the primary user terminal device 4, when copied to the recording medium 11, the secondary user terminal device 5 via the communication network 8 When transferred to, the data M is encrypted by the copyright management program P using the second private key Ks2. Cmks2 = E (Ks2, M)
The encrypted data Cmks2 is copied to the recording medium 11 together with the original data name or the original data number, or transferred to the secondary user terminal device 5 via the communication network 8.
The secondary user who has obtained the encrypted data Cmks2 uses the secondary user terminal device 5 to specify the original data name or the original data number to write the secondary use of the data M, which is the original data or the processed data. Apply to the rights management center 18.
The secondary copyright management center 18 that received the secondary use application of data M searches for the first private key Ks1 using the original data name or the original data number as a clue, and based on the first private key Ks1, the second private key Ks2. Is generated, and Ks2 = P (Ks1) The generated second private key Ks2 is supplied to the secondary user terminal device 5 together with the copyright management program P.
The secondary user terminal device 5 that has received the second private key Ks2 and the copyright management program P decrypts the encrypted data Cmks2 using the copyright management program P and uses the second private key Ks2 to decrypt M = D. (Ks2, Cmks2) The decrypted M is used as it is or after processing. When data M is stored in the secondary user terminal device 5, copied to the recording medium 12, or transferred to the tertiary user terminal device 6 via the communication network 8.
The copyright management program P generates a third private key Ks3 based on the second private key Ks2, and Ks3 = P (Ks2) The copyright management program P uses this generated third private key Ks3 to generate data M. Be encrypted. Cmks3 = E (Ks3, M)
[Example 9] In Example 9 described below, the original data supplied from a single database is supplied in response to a request from the user, as in Example 8 shown in FIG. The encryption method adopted in this embodiment is a private key method, and user data is used in addition to the first private key used in the eighth embodiment to generate the second private key. Since the system configuration of this embodiment is not different from the system configuration of the eighth embodiment, the description of the system configuration will be omitted.
The original data M0 is stored in database 1 in an unencrypted state. When the primary user accesses the database 1 using the primary user terminal device 4, the data menu is transferred. At this time, the charge information may be displayed together with the data menu.
When the data menu is transferred, the primary user searches the data menu, selects the original data M0, and specifies the original data name of the selected original data M0, etc., so that the primary user of the original data M0 is assigned to the database 1. Apply for use.
In the database 1 that received the application for use of the original data M0 from the primary user terminal device 4, the original data M0 is read, the read original data M0 is encrypted with the first private key Ks1, and Cm0ks1 = E ( Ks1, M0) The copyright management program P is supplied to the primary user terminal device 4 together with the encrypted original data Cm0ks1 and the first private key Ks1.
The copyright management program P used here is common to all database organizations, and also includes a cryptographic program having a cryptographic algorithm, which performs cryptographic generation and data decryption / encryption. It is said.
The primary user terminal device 4 that has received the first private key Ks1 and the copyright management program P decrypts the original data Cm0ks1 encrypted by the copyright management program P using the first private key Ks1 and M0 = D. (Ks1, Cm0ks1) The decrypted original data M0 is used as it is or as processed data M1. In addition, the copyright management program P generates the second private key Ks2 based on the primary user information Iu1. Ks2 = P (Iu1) This second private key Ks2 can also be generated based on the first private key Ks1 or the primary user data Iu1 and the first private key Ks1 in addition to the primary user information Iu1. Ks2 = P (Ks1) Ks2 = P (Ks1 + Iu1)
When the original data M0 or the data M which is the processed data M1 is stored in the primary user terminal device 4, when copied to the recording medium 11, it is transferred to the secondary user terminal device 5 via the communication network 8. If so, the data M is encrypted by the copyright management program P with the second private key Ks2. Cmks2 = E (Ks2, M)
The data Cmks2 encrypted by the second private key Ks2 is given the original data name or the original data number, is copied to the recording medium 11, or is sent to the secondary user terminal device 5 via the communication network 8. Transferred.
The secondary user who obtained the data Cmks2 encrypted by the second private key Ks2 applies for the secondary use of the data M to the copyright management center 18 using the secondary user terminal device 5, but at this time, the original Specify the data name or original data number, and present the unencrypted primary user information Iu1.
The copyright management center 18 that received the secondary use application of the data M searches for the first private key Ks1 by the specified original data name or the original data number, and the primary user information Iu1 presented by the copyright management program P. The second private key Ks2 is generated based on the found first private key Ks1 and supplied to the secondary user terminal device 5 together with the copyright management program P.
The secondary user who received the second private key Ks2 and the copyright management program P uses the secondary user terminal device 5, and the data Cmks2 encrypted by the copyright management program P using the second private key Ks2. Is decrypted, and M = D (Ks2, Cmks2) decrypted data M is used as it is or after being processed. When the data M is stored in the secondary user terminal device 5, copied to the recording medium 11, or transferred to the tertiary user terminal device 6 via the communication network 8, the data M is It is encrypted by the second private key Ks2 by the copyright management program P. Cmks2 = E (Ks2, M)
In this case, the copyright management program P generates the third private key Ks3 based on the primary user information Iu1 and the second private key Ks2 or the primary user information Iu1 and the second private key Ks2. Ks3 = P It is also possible to set (Iu1) Ks3 = P (Iu1 + Ks1) Ks3 = P (Ks1). It is also possible to present the secondary user information Iu2 when the secondary user makes a secondary usage application, and generate a third private key based on the secondary user information Iu2 instead of the primary user information Iu1. Data M is encrypted by the copyright management program P with the third private key Ks3. Cmks3 = E (Ks3, M)
In this embodiment, since the copyright management program P that generates the second private key Ks2 is common to all database organizations, the primary user data Iu1 and the first private key Ks1 are not changed in any database organization. As long as the same original data is used, the same second private key Ks2 is generated.
[Example 10] In Example 10 described below, the original data is supplied from a single database in response to a request from the user, as in Example 8 shown in FIG. The encryption method adopted in this embodiment is a private key method. In this embodiment, the number of times the copyright management program is used is used instead of the user information used in the ninth embodiment to generate the second private key. Since the system configuration of this embodiment is not different from the system configuration of the eighth embodiment, the description of the system configuration will be omitted.
The original data M0 is stored in database 1 in an unencrypted state. When the primary user accesses the database 1 using the primary user terminal device 4, the data menu is transferred. At this time, the charge information may be displayed together with the data menu.
When the data menu is transferred, the primary user searches the data menu, selects the original data M0, and uses the primary user terminal device 4 to refer to the database 1 via the communication network 8 with the original data name. Apply for the use of the original data M0 that you want to use for the first time.
Database 1, which received a data usage application from the primary user, encrypts the original data M0 with the first private key Ks1 and copyrights it together with the encrypted data Cm0ks1 and the first private key Ks1. The management program P is supplied to the primary user terminal device 4.
This copyright management program P includes a cryptographic program having a cryptographic algorithm, and this cryptographic program performs encryption key generation and data decryption / encryption. A counter is attached to the copyright management program P, and this counter counts the number of times the program is used N or the number of times the original data is used N. If this encryption algorithm depends on the first private key Ks1, the copyright management program P can be unique to the original data.
The primary user who receives the first private key Ks1 and the copyright management program P decrypts the encrypted original data Cm0ks1 using the copyright management program P using the first private key Ks1 and M0 = D (Ks1, Cm0ks1) The decrypted original data M0 is used as it is or as processed data M1.
In order to protect the copyright of the data, when the original data M0 or the data M which is the processed data M1 is stored in the primary user terminal device 4, copied to the recording medium 11, or is copied to the recording medium 11, via the communication network 8. When transferred to the secondary user terminal device 5, the data M is encrypted by the copyright management program P. In other words, the copyright management program runs whenever these uses are made.
On the other hand, when the supplied copyright management program P is used, the counter in the program counts, and the copyright management program P generates the second private key Ks2 based on the count number N and the first private key Ks1. To do. Ks2 = P (N + Ks2)
Since this second private key Ks2 is also based on the number of times N of the copyright management program P has been used, the data M is encrypted with the new second private key Ks2 each time it is used. Cmks2 = E (Ks2, M) The data Cmks2 encrypted by the second private key Ks2 generated last is stored in the recording medium 11 together with the original data name or the original data number, the primary user information Iu1 and the counter data N. It is copied or transferred to the secondary user terminal device 5 via the communication network 8.
The secondary user who obtained the data Cmks2 encrypted using the second private key Ks2 presents the original data name or the original data number, the primary user information Iu1 and the counter data N, and secondary uses the data M. Apply to the Copyright Management Center 18.
The copyright management center 18 that received the secondary use application of the encrypted data Cmks2 searched for the first private key Ks1 from the original data name or the original data number of the data, and presented the first private key. The second private key Ks2 is generated from the primary user information Iu1 and the counter data N, and the generated second private key Ks2 is transferred to the secondary user terminal device 5 together with the copyright management program P.
The secondary user terminal device 5 that has received the second private key kS2 and the copyright management program P decrypts the encrypted data Cmks2 using the copyright management program P using the second private key Ks2 and M = D (Ks2, Cmks2) Decrypted data M is used as it is or after processing.
If the data is stored in the secondary user terminal device 5, copied to the recording medium 12, or transferred to the tertiary user terminal device 6 via the communication network 8, the data is copyrighted. It is encrypted by the management program with a second private key.
In addition, the copyright management program can also generate a third private key based on the second private key.
All of Examples 1 to 10 described above are for the case of using the single original data supplied from the database. However, in processing as a form of data usage, in addition to processing a single data, when creating new data by combining multiple original data obtained from the same database, or when creating new data, or when multiple originals obtained from multiple databases are used. Data may be combined to create new data.
[Example 11] Example 11 described below is an example in which a primary user creates new data by combining a plurality of original data stored in a single database, and the primary user is stored in the database. Create new data using the stored first, second, and third original data as materials.
In this embodiment, as in Example 8 shown in FIG. 4, a plurality of original data are supplied from a single database in response to a user request. The encryption method adopted in this embodiment is a private key method. Since the system configuration of this embodiment is not different from the system configuration of the eighth embodiment, the description of the system configuration will be omitted.
The original data M01, M02, and M03 are stored in database 1 in an unencrypted state. When the primary user accesses the database 1 using the primary user terminal device 4, the data menu is transferred. At this time, the charge information may be displayed together with the data menu.
When the data menu is transferred, the primary user searches the data menu, selects the original data M01, M02, M03, and uses the primary user terminal device 4 to search the database 1 via the communication network 8. , 1st, 2nd, 3rd original data Specify the original data name or original data number of M01, M02, M03 and apply for the supply of each original data. At this time, the primary user information Iu1 is presented.
The database 1 that received the supply application of the first, second, and third original data M01, M02, and M03 from the primary user is the first, second, and third original data M01, M02, that received the supply application. Encrypt M03 using the first, second, and third private keys Ks01, Ks02, and Ks03, respectively, and Cm01ks01 = E (Ks01, M01) Cm02ks02 = E (Ks02, M02) Cm03ks03 = E (Ks03, M03) The first, second, and third private keys Ks01, Ks02, Ks03, and the copyright management program P common to all database organizations and all original data are supplied to the primary user terminal device 4. This copyright management program P includes a cryptographic program having a cryptographic algorithm, and cryptographic key generation and decryption / encryption are performed.
Received encrypted 1st original data Cm01ks01, encrypted 2nd original data Cm02ks02, encrypted 3rd original data Cm03ks03, 1st private key Ks01, 2nd private key Ks02, 3rd private key Ks03, copyright management program P The primary user terminal device 4 uses the copyright management program P to decrypt the first, second, and third encrypted original data Cm01ks01, Cm02ks02, and Cm03ks03 using these private keys Ks01, Ks02, and Ks03. M01 = D (Ks01, Cm01ks01) M02 = D (Ks02, Cm02ks02) M03 = D (Ks03, Cm03ks03) Process the original data M01, M02, M03 to create new data M1.
In addition, the copyright management program P is based on one of the first private key Ks01, the second private key Ks02, the third private key Ks03, and the primary user data Iu1 or some of them, and the fourth private key Ks4. To generate. Ks4 = P (Ks01 / Ks02 / Ks03 / Iu1)
When the processed data M1 is stored in the primary user terminal device 4, copied to the recording medium 11, or transferred to the secondary user 5 via the communication network 8, the copyright management program P Encrypted by the 4th private key Ks4. Cm1ks4 = E (Ks4, M1)
The encrypted data Cm1ks4 is copied to the recording medium 11 or transferred to the secondary user terminal device 5 via the communication network 8 together with the original data name or the original data number and the primary user data Iu1.
The secondary user who obtained the encrypted processing data Cm1ks4 applies to the copyright management center 18 for the secondary use of the encrypted processing data Cm1ks4 using the secondary user terminal device 5, but at this time, the original data M01, M02, Specify the data name or data number of M03 and present the primary user information Iu1.
The copyright management center 18 that received the secondary usage application for the encrypted data Cm1ks4 from the secondary user searches for the first private key Ks01 from the data name or data number of the first original data M01, and finds the first private key Ks01 from the second original data M02. The second private key Ks02 is searched from the data name or data number, the third private key Ks03 is searched from the data name or original data number of the third original data M03, and the first found by the common copyright management program P. Private key Ks01, 2nd private key Ks02, 3rd private key Ks03, Primary user information Generate 4th private key Ks4 based on one of or some of Iu1 and Ks4 = P (Ks01 / Ks02 / Ks03 / Iu1) Provide to secondary user 5 together with common copyright management program P.
The secondary user who receives the copyright management program common to the fourth private key decrypts the processed data M1 using the fourth private key Ks4 by the copyright management program P and decrypts M1 = D (Ks4, Cm1ks4). The processed processing data M1 is used as it is or as reprocessing data M2.
When the processed data M1 or the reprocessed data M2 is stored in the secondary user terminal device 5, copied to the recording medium 12, or transferred to the tertiary user 6 via the communication network 8. The copyright management program P generates the fifth private key Ks5 based on the fourth private key Ks4, and Ks5 = P (Ks4). The data is encrypted by the copyright management program P using the fifth private key Ks5. To. Cm1ks5 = E (Ks5, Cm1) Cm2ks5 = E (Ks5, Cm2)
The common copyright management program P uses the 4th private key Ks4 to generate the 5th private key Ks5, and the generated 5th private key Ks5 is used for subsequent encryption / decryption. You can also do it.
In this embodiment, since the copyright management program that generates the fourth private key is common to all database organizations, it is the same in all database organizations unless the primary user data and the first private key are changed. The same fourth private key is generated for the original data of.
Although the common copyright management program in this embodiment is supplied from the copyright management center 18, it may be built in the ROM in each user terminal device or in the software for using the database.
[Example 12] In the 12th embodiment described below, a plurality of original data supplied from a plurality of databases according to a user's request are combined to create new data. In this embodiment, encryption is performed. The private key method is adopted as the key method.
In FIG. 5, 19, 20, 21 are the first, second and third databases in which text data, computer graphics screen or computer program binary data, audio data or video data are stored, and 4 is the primary user. Terminal equipment, 5 is a secondary user terminal equipment, 6 is a tertiary user terminal equipment, 7 is an nth user terminal equipment, 10 is a copyright management center that manages data copyrights, and 8 is provided by a telecommunications carrier. It is a communication network such as a public line or a CATV line provided by a cable television operator.
Of these, the 1st, 2nd and 3rd databases 19,20,21, the copyright management center 10, the primary user terminal device 4, the secondary user terminal device 5, the tertiary user terminal device 6 and the nth user terminal device 7 are connected to each other by the communication network 8.
Each user who uses this system needs to be registered in each database organization in advance. In addition, at the time of this registration, the software used by each database organization is supplied to the user. This software includes ordinary communication software programs such as data communication protocols. These database organization use software may be stored in a fixed disk in the user terminal device, but may also be stored in a mask ROM, EPROM, EEPROM or the like built in the user terminal device.
Further, in this system, the encryption key generation algorithm is stored in the user terminal device in order to generate the private key on the user side, but since the encryption key generation algorithm itself is not necessarily secret, each database organization is used. It may be built into the software. In the case of original data supplied free of charge, such as with advertisements, encryption may not be required, but even in that case, the copyright exists, so procedures for using the copyright are necessary. .. In this figure, the route shown by the broken line is the route of the encrypted data, and the route shown by the solid line is the route for making a request from each user terminal device to each database and copyright management center. The route indicated by the chain line is the route through which the permission information, the copyright management program, and the encryption key corresponding to the usage pattern are transferred from each database and the copyright management center to each user terminal device.
In this embodiment, different private keys and copyright management programs are used for each original data, but these are stored in each database and copyright management center in advance.
The first original data M1 is stored in the first database 19 in an unencrypted state, and when the primary user accesses the first database 19 using the primary user terminal device 4, the data menu is displayed. Transferred.
When the data menu is transferred, the primary user searches the data menu, selects the first original data M1, and uses the primary user terminal device 4 to search the first database 19 via the communication network 8. , Specify the original data name or the original data number and apply for the supply of the first original data M1, but at this time, the primary user information Iu1 is presented.
The first database 19 that received the usage application of the first original data M1 from the primary user encrypts the first original data M1 that received the usage application using the first private key Ks1, and Cm1ks1 = E (Ks1, M1) Supply to the primary user terminal device 4.
The second original data M2 is stored in the second database 20 in an unencrypted state, and when the primary user accesses the second database 20 using the primary user terminal device 4, the data menu is displayed. Transferred.
When the data menu is transferred, the primary user searches the data menu, selects the second original data M2, and uses the primary user terminal device 4 to the second database 20 via the communication network 8. , Specify the original data name or the original data number and apply for the supply of the second original data M2, but at this time, the primary user information Iu1 is presented.
The second database 20 that received the usage application for the second original data M2 from the primary user encrypts the second original data M2 that received the usage application using the second private key Ks2, and Cm2ks2 = E (Ks2, M2). ) Supply to the primary user terminal device 4.
The second original data M3 is stored in the third database 21 in an unencrypted state, and when the primary user accesses the third database 21 using the primary user terminal device 4, the data menu is displayed. Transferred.
When the data menu is transferred, the primary user searches the data menu, selects the third original data M3, and uses the primary user terminal device 4 to the third database 22 via the communication network 8. , Specify the original data name or the original data number and apply for the supply of the third original data M3, but at this time, the primary user information Iu1 is presented.
The third database 21 that received the usage application for the third original data M3 from the primary user encrypts the third original data M3 that received the usage application using the third private key Ks3, and Cm3ks3 = E (Ks3, M3). ) Supply to the primary user terminal device 4.
The primary user supplied with the encrypted first, second, and third original data Cm1ks1, Cm2ks2, and Cm3ks3 uses the primary user terminal device 4 to encrypt the first, second, and third original data Cm1ks1. In order to use Cm2ks2 and Cm3ks3 for the primary use, specify the original data name or the original data number via the communication network 8 and apply for the primary use to the copyright management center 10.
Encryption from the primary user The copyright management center 10 that received the primary usage application for the primary data Cm1ks1, Cm2ks2, and Cm3ks3 is the first secret that is the encryption key for the primary data M1. The third private key Ks3, which is the encryption key of the second copyright management program P2 and the third original data M3, together with the second private key Ks2, which is the encryption key of the first copyright management program P1 and the second original data M2 together with the key Ks1. At the same time, the third copyright management program P3 is supplied to the primary user terminal device 4.
These copyright management programs P1, P2, and P3 each include a cryptographic program having a cryptographic algorithm, and these cryptographic programs generate a new private key and decrypt / encrypt data. If these cryptographic algorithms depend on the first, second, and third private keys Ks1, Ks2, and Ks3, respectively, the first, second, and third copyright management programs P1, P2, and P3 can be used. It can be unique to each of the first, second, and third original data M1, M2, and M3.
The primary user terminal device 4 that has received the first, second, and third private keys Ks1, Ks2, and Ks3 has the first, second, and third original data encrypted using these private keys. Decrypt Cm1ks1, Cm2ks2, Cm3ks3 and process M1 = D (Ks1, Cm1ks1) M2 = D (Ks2, Cm2ks2) M3 = D (Ks3, Cm3ks3) decrypted original data M1, M2, M3 as they are And use it. In addition, the first copyright management program P1 obtains the fourth private key Ks4 based on the first private key Ks1, and the second copyright management program P2 obtains the fifth private key Ks5 based on the second private key Ks2. 3 The copyright management program P3 generates the sixth private key Ks6 based on the third private key Ks3. Ks4 = P1 (Ks1) Ks5 = P2 (Ks2) Ks6 = P3 (Ks3)
When each original data M1, M2, M3 or processed data M4, M5, M6 is stored in the primary user terminal device 4, copied to the recording medium 11, the secondary user terminal via the communication network 8 When transferred to the device 5, the first original data M1 or the processed data M4 is the first copyright management program P1 using the fourth secret key Ks4, and the second original data M2 or the processed data M5 is the second. 2 The third original data M3 or the processed data M6 is encrypted by the third copyright management program P3 using the fifth private key Ks5 by the copyright management program P2, and each is encrypted by the third copyright management program P3 using the sixth private key Ks6. Cm1ks4 = E (Ks4, M1) Cm2ks5 = E (Ks5, M2) Cm3ks6 = E (Ks6, M3) Cm4ks4 = E (Ks4, M4) Cm5ks5 = E (Ks5, M5) Cm6ks6 = E (Ks6, M6)
The original data Cm1ks4, Cm2ks5, Cm3ks6 encrypted by the 4th, 5th and 6th private keys Ks4, Ks5, Ks6 or the encrypted processed data Cm4ks4, Cm5ks5, Cm6ks6 are the 1st, 2nd and 3rd originals. Together with the data name or original data number and the primary user data Iu1, it is copied to the recording medium 11 or transferred to the secondary user terminal device 5 via the communication network 8.
In the secondary user terminal device 5 supplied with the encrypted first, first, second, and third original data Cm1ks4, Cm2ks5, Cm3ks6 or the encrypted processed data Cm4ks4, Cm5ks5, Cm6ks6, the original data name or original By specifying the data number, apply to the copyright management center 10 for the secondary use of the first, second, and third original data M1, M2, M3 or the processed data M.
The copyright management center 10 that receives the secondary usage application of the first, second, and third original data M1, M2, M3 or the processing data M4, M5, M6 from the secondary user terminal device 5 is the first source. Find the first private key Ks1 and the first copyright management program P1 from the data name, find the second private key Ks2 and the second copyright management program P2 from the second original data name or the original data number, and find the third source. The third private key Ks3 and the third copyright management program P3 are searched for from the data name, the first copyright management program P1 generates the fourth private key Ks4 from the first private key Ks1, and the second copyright management program P2 The 5th private key Ks5 is generated from the 2nd private key Ks2, the 3rd copyright management program P3 generates the 6th private key Ks6 from the 3rd private key, and Ks4 = P1 (Ks1) Ks5 = P2 (Ks2). Ks6 = P3 (Ks3) Supply to the secondary user terminal device 5 together with the first, second, and third copyright management programs P1, P2, and P3.
In the secondary user terminal device 5 that received the 4th, 5th, 6th private keys Ks4, Ks5, Ks6 and the 1st, 2nd, and 3rd copyright management programs P1, P2, P3, the encrypted 1st The original data Cm1ks4 or the processed data Cm4ks4 is encrypted by the first copyright management program P1 using the fourth private key Ks4, and the second original data Cm2ks5 or the processed data Cm5ks5 is encrypted by the second copyright management program P2. 5 The third original data Cm3ks6 or the processed data Cm6ks6 encrypted using the private key Ks5 is decrypted by the third copyright management program P3 using the sixth private key Ks6, and M4 = D (Ks4). , Cm4ks4) M5 = D (Ks5, Cm5ks5) M6 = D (Ks6, Cm6ks6) Each decrypted data M4, M5, M6 is used as it is or after processing.
When the first, second, and third original data M1, M2, M3 or the processed data M4, M5, M6 are stored in the secondary user terminal device 5, copied to the recording medium 12, the communication network 8 When the data is transferred to the secondary user terminal device 6 via the above, the first source data M1 or the processed data M4 is the second source using the fourth secret key Ks4 by the first copyright management program P1. Data M2 or processed data M5 uses the 5th secret key Ks5 by the 2nd copyright management program P2, and 3rd original data M3 or processed data M6 uses the 6th secret key Ks6 by the 3rd copyright management program P3. And each is encrypted.
In this case, the first copyright management program P1 obtains the seventh private key Ks7 based on the fourth private key Ks4, and the second copyright management program P2 obtains the eighth private key Ks8 based on the fifth private key Ks5. The third copyright management program P3 generates each of the ninth private key Ks9 based on the sixth private key Ks6, and Ks7 = P1 (Ks4) Ks8 = P2 (Ks5) Ks9 = P3 (Ks6). When the second and third original data M1, M2, M3 or processed data M4, M5, M6 are stored in the secondary user terminal device 5, copied to the recording medium 12, via the communication network 8. When the data is transferred to the tertiary user terminal device 6, the first, second, and third original data M1, M2, M3 or the processed data M4, M5, M6 are the first, second, and third works. It can also be encrypted using the 7th, 8th, and 9th private keys Ks7, Ks8, and Ks9 by the rights management programs P1, P2, and P3. Cm1ks7 = E (Ks7, M1) Cm2ks8 = E (Ks8, M2) Cm3ks9 = E (Ks9, M3) Cm4ks7 = E (Ks7, M4) Cm5ks8 = E (Ks8, M5) Cm6ks9 = E (Ks9, M6)
[Example 13] Example 13 described below is an example in which new data is created by using a plurality of original data supplied from a plurality of databases in response to a user's request, as in the case of the twelfth embodiment. , In this embodiment, the private key method is adopted as the encryption key method. Further, as in the case of Example 7 and Example 11, the number of times the copyright management program is used is further used to generate the encryption key used for encryption / decryption.
In this embodiment, the copyright management program is attached with a counter, which counts the number of times the program is used or the number of times the original data is used, and uses the number N of the counters to use the fourth, fifth, and fifth. The sixth private key Ks4, Ks5, Ks6 is generated. The secondary user presents the original data name or original data number of each original data, the number of counters N together with the primary user data, and applies for the secondary use of the data to the copyright management center 10. The copyright management center 10 that receives the secondary use application for the data searches for the first, second, and third private keys Ks1, Ks2, and Ks3 from each original data name or original data number, and searches for the first, second, and third secret keys. 3rd copyright management program P1, P2, P3, 1st, 2nd, 3rd private key of each data Ks1, Ks2, Ks3, primary user Iu1 and 1st, 2nd, 3rd counter number N1, N2 Generates the 4th, 5th, and 6th private keys Ks4, Ks5, and Ks6 from N3, and provides them to the secondary user together with the 4th, 5th, and 6th copyright management programs P1, P2, and P3. Since there are no other points different from the system configuration of the twelfth embodiment, specific description thereof will be omitted.
[Example 14] When the original data obtained by the primary user is copied as it is and supplied to the secondary user, no value is added to the data, so that the copyright of the primary user is added to the data. Does not occur. However, when new data is created from the obtained original data, that is, when new data is created from the obtained single original data and when new data is created from multiple obtained original data, the new data Secondary copyright of the primary user occurs.
On the other hand, since the original copyright used for processing also has the copyright of the original copyright holder, the processed data includes the original copyright of the author of the original data and the secondary of the primary user who performed the processing. There will be copyright. Since copyright is not just a property right but a right with a strong element of personality rights, the author often insists on its existence. Therefore, even when the original data is processed, it is desirable to be able to easily identify the original data or the copyright holder from the processed data.
In the data copyright management system described in Examples 1 to 13 so far, the copyright of the data is managed by encrypting the original data or the processed data. Is the data the original data in this system? Alternatively, since the copyright of the data is managed without distinguishing whether it is the processed data, which part of the processed data is the original data, and which part is the processed data, the original data is used as the original data. It is not possible to identify the data or the copyright holder.
In Example 14 described below, the data can be distinguished from the original data in which only the original copyright exists and the processed data in which the secondary copyright exists in addition to the original copyright, and the original copyright and the secondary copyright are clarified. Can be managed.
Since data processing is performed by modifying the original data using a processing program, the processing data is reproduced by specifying the original data and the processing content (and the processing program if necessary). .. In other words, it is impossible to reproduce the machining data unless the original data and the machining content (and the machining program if necessary) are specified. The secondary copyright management described in Example 14 is performed by identifying the original data and the processing content (and a processing program if necessary) and managing them.
When creating new data from a single original data, when modifying the original data A to obtain the processed data "A'", the primary user adds the data X to the original data A to obtain the processed data "A'". To obtain "A + X", divide the original data A into the original data elements A1, A2, A3 ... and change the array to A3, A2, A1 to obtain the processing data "A" ". Data A is divided into original data elements A1, A2, A3 ..., primary user data X is divided into X1, X2, X3 ..., and these are arranged to process data "A1 + X1 + A2 + X2". + A3 + X3 ... "may be obtained. In these cases, modification of the original data, rearrangement of the original data, combination of the original data and the primary user data, division of the original data and combination of the primary user data are subject to secondary copyright, respectively. It is necessary to protect the secondary copyright of. Needless to say, the original copyright of the primary user exists in the data X added by the primary user.
When creating new data by combining multiple original data, when obtaining processing data "A + B + C ..." by simply combining the original data A, B, C ..., the original data When the primary user obtains the processing data "A + X" by adding the data X to A, B, C ..., the original data A, B, C ... are added to the original data elements A1, A2, A3., B1, B2, B3 , C1, C2, C3 Divided and combined to change the arrangement and processing data A1 + B1 + C1 + + A2 + B2 + C2 + When "+ A3 + B3 + C3 + ..." is obtained, the original data A, B, C ... are converted into the original data elements A1, A2, A3 ..., B1, B2, B3 ..., C1, C2, Divide into C3 ... and combine the primary user data X1, X2, X3 ... to change the array and change the processing data "A1 + B1 + C1 + X1 + ... + A2 + B2 + C2 + X2 + ... + A3 + B3 + C3 + X3 + ... may be obtained. In these cases as well, the combination of multiple original data, the combination of multiple original data and primary user data, the division and rearrangement of multiple original data, and the combination of multiple divided original data and primary user data are Each is subject to secondary copyright and it is necessary to protect these secondary copyrights. Further, it goes without saying that the original copyright of the primary user exists in the data X1, X2, X3 ... Added by the primary user.
Figure 6 shows an example of a method for creating new data D using multiple original data A, B, and C. This method extracts (cuts) elements a, b, c from the original data A, B, C, pastes the extracted elements a, b, c (paste), and synthesizes one data D. Cut and paste Data is processed by a method.
By the way, although it is clear that the original data and the primary user data are data, the modification of the original data in the process of processing the data, the change of the arrangement of the original data, the combination of the original data and the primary user data, and the original data Division and combination with primary user data, combination of multiple original data, combination of multiple original data and primary user data, division and rearrangement of multiple original data, multiple divided original data and primary user The combination of data is also the data itself.
In Examples 1 to 13 described so far, the copyright of the data itself is managed by encrypting the original data or the processed data, but in addition to this, the arrangement relationship and processing of the original data Focusing on the fact that the processing process of data such as procedures is also data, the secondary copyright related to the processed data is the primary copyright of the original author regarding the original data and the primary copyright of the primary user regarding the primary user data. In addition, it is possible to protect by managing the primary copyright of the primary user regarding the processing process data. The machining process and machining program can also be called a machining scenario.
That is, the machining data is composed of the original data, the primary user data, and the machining process data, and these original data, the primary user data, and the machining process data are the data described in Examples 1 to 13, respectively. By managing by the copyright management system, the copyright of the processed data as well as the original data can be sufficiently managed. In this case, the processing program used in data processing is also subject to management by the data copyright management system if necessary.
This data can be processed by using the processing program corresponding to the original data, but if the original data is treated as object-oriented software that has been attracting attention recently, it will be easier to process. Better data rights management can be done. Further, if agent-oriented software is adopted further, the user can synthesize data without any effort.
Agent-oriented software is a program that combines autonomy, adaptability, and cooperation, and is based only on the general instructions of the user without specifically instructing all work procedures as in conventional software. Due to its autonomy, adaptability, and cooperativeness, it is possible to meet the needs of users. This agent program is incorporated into the basic system of the data copyright management system, the user's database usage pattern is monitored, and the information obtained as a result is collected on the database side or the copyright management center side. As a result, the database side or the copyright management center side can know the user's database usage tendency, and more detailed copyright management can be performed. Therefore, the agent program and data are also subject to copyright protection and are encrypted in the same way as the original data.
[Example 15] Some of the works do not have a copyright and some have a copyright, and some of the works that have a copyright are those in which the copyright is exercised and those in which the copyright exists. Some are not exercised. Copyright-free works include works that are not copyrighted by law and those whose copyright has expired. All works except these non-copyrighted works have copyrights, but copyrighted works are usually labeled as claiming the existence of copyrights. By being there, the deterrent effect against copyright infringement is exerted. This also applies when the work is data, and in the case of data with copyright, the copyright is displayed or the copyright holder is displayed on the data to be used or the file header of the data. Deters data copyright infringement. Further, by adding a copyright flag indicating that the data has a copyright to the file and identifying this flag in the user terminal device, it is possible to prevent the infringement of the data copyright.
However, even if such a copyright is displayed, if the user who uses the data work ignores the existence of the copyright, the copyright may be infringed. In order to deal with such a case, in the embodiment described so far, the data is encrypted, the decryption key for decrypting the encrypted data is managed, and the decrypted data is stored, copied, and transferred. Is encrypted / decrypted using an encryption key different from the decryption key. Even in such a case, by transferring the data to a storage device other than the main storage device of the user terminal device while the data exists on the main storage device of the user terminal device, a code different from the decryption key is used. The possibility of storing, copying and transferring data without the use of a key cannot be completely ruled out.
To prevent such a situation, incorporate the data copyright use software into the basic system of the user terminal device, display the copyright exercise attribute on the file of the data work subject to copyright exercise, and display the data copyright. It is best that the basic system of the user terminal device monitors the copyright enforcement attribute of the object, and that the data work having the copyright enforcement attribute is managed by the data copyright utilization software. The basic system is a software operating system such as DOS when the user terminal device is a computer such as a personal computer, and ROM when the user terminal device is a mobile information terminal device or STB (set top box). It is a built-in hardware operating system. In order to strengthen the data copyright management by this operating system, it is desirable to incorporate the data copyright utilization software at the highest level possible in the operating system.
All processing and data inside the user terminal device is under the control of the operating system. In other words, the operating system can keep track of all the processing and data inside the user terminal equipment. Therefore, the copyright management program can automatically manage the data copyright according to the data usage status grasped by the operating system, not according to the user's instruction. According to such a configuration, The data copyright can be easily used by the user, and more complete data copyright management can be performed. Further, it is desirable that the copyright management program that manages the encryption key, data copyright information, copyright label, etc. is held in the system area managed by the operating system itself, in other words, in the system area that the user program cannot access.
However, even in this case, if only a part of the data work is cut off and used, the management of the data copyright becomes extremely difficult. Therefore, when the operating system recognizes such a situation, it is configured to add the copyright information and copyright exercise attribute that the original data had to some data cut by the copyright management program. By doing so, it becomes possible to manage the data copyright of some of the cut data. In addition, in order for the cut data to inherit the copyright of the original data work, a copyright management program forms a parent-child relationship link between the cut data and the original data work. By doing this, even if the user cuts out the desired part from multiple copyrighted data and imports it to create new data, the new data can inherit the copyright of each original data copyrighted material. Can be done.
[Example 16] Since copyright is a kind of property right, the problem of payment of royalties naturally occurs when using copyright. In addition, services such as the provision of private keys and the provision of copyright management programs need to be provided for a fee. The simplest method of paying these fees is a combination of issuing an invoice and paying, but while this method pays the usage fee directly, the work is complicated and accidents such as non-payment are possible. There is also sex. There is also a fee collection agency method performed by the communication line operator, which is convenient because the communication line operator performs the fee collection work, and while the possibility of accidents such as non-payment is low, the usage fee is directly collected. Since it is not done in, it is necessary to pay the fee collection agency fee.
As a method of solving these problems, there is a method of using a digital cache. This digital cache is digital data and is encrypted and used.
[Example 17] Further, the configuration of the data copyright management system described above can be applied not only to the distribution of data but also to the distribution of digital cache. Various digital cash systems that have been proposed so far transfer encrypted digital cash data using a private key method from a bank deposit account or a cash advance of a credit company and store it in an IC card. Use to pay. A digital cash system that uses this IC card as an electronic wallet can be used anywhere an input / output terminal device is installed, such as a store, but on the other hand, a place without an input / output terminal device, such as a home, etc. , Cannot be used.
By the way, since the digital cache is encrypted data, any device other than the IC card that can store the encrypted data and can transfer the data to the payee can store the digital cache data. It can be used as an electronic wallet to store. Specifically, user terminal devices that can be used as electronic wallets include personal computers, intelligent television devices, mobile information terminal devices (Personal Digital Assistant PDA), PHS (Personal Hadyphone System) and other mobile phones, intelligent telephones, and inputs. There are PC cards that have an output function.
In transactions by using such a terminal device as an electronic wallet for digital cash, the database 1 in the configuration of the data copyright management system described above is used as the customer bank, and the primary user terminal device 4 is used as the customer. , The secondary user terminal device 5 is replaced by a retail store, the copyright management center 18 is replaced by a retail store bank, and the tertiary user terminal device 6 is replaced by a wholesaler or a manufacturer.
In addition, it is desirable that the digital cache is processed not as mere data but as an object in which data and functions are linked. In the handling of digital cache, common digital cash form, owner-specific blank digital cash form, owner-specific digital cash form entry field, digital cache data that is the amount of money, instructions for handling digital cache, amount of money are written. There is an owner-specific digital cash form. On the other hand, object-oriented programming (object-oriented) In programming, the concepts of object, class, slot, message, and instance are used. In these correspondences, the common digital cache form becomes an object, the owner-specific blank digital cache form becomes a class, the owner-specific digital cache form entry field becomes a slot, and the instruction to handle the digital cache becomes a message. , The owner-specific digital cash form with the amount entered becomes the instance. Digital cache data consisting of monetary amounts, etc. is used as an argument, and is passed to a slot called an instance variable by a message and stored, so that a new instance, which is a digital cache with updated monetary amounts, etc., is created. Made.
The objectified digital cache will be specifically described with reference to FIG. In this figure, 23, 25, 27 are customer-specific digital cash forms with the amount stored in the customer terminal device, and 29 are retailer-specific digital cash forms with the amount stored in the retail store terminal device. Digital Cash Forms, 24, 26, 28 are deposit accounts at each customer's bank.
The customer 23 withdraws the required amount from the deposit account 24 in order to use the digital cash, and delivers the digital cash withdrawal data 31 to the digital cash form 23 stored in the terminal device. In this case, the digital cache form 23 is not a class but an instance because the digital cache balance data 30 is usually already filled in the digital cache form 23. The digital cash withdrawal data 31 is delivered as an argument to the slot which is the entry field of the digital cash form 23 by the message instructing to add to the digital cash balance data 30, and is passed to the digital cash balance data 30 of the digital cash form 23. The digital cash withdrawal data 31 is added and a new instance is created in which the amount in the entry field of the digital cash form 23 is changed.
When the customer pays to the retail store, in the digital cash form entry field by a message instructing to subtract the digital cash payment data 32 corresponding to the payment amount from the amount in the entry field of the digital cash form 23. It is delivered as an argument to a certain slot, and the digital cash payment data 32 is subtracted from the digital cash balance data 30 and the digital cash withdrawal data 31 of the digital cash form 23, and the amount in the entry field of the digital cash form 23 is changed. An instance is created. In addition, the digital cash payment data 32 is delivered to the retail store-specific digital cash form 29.
Similar withdrawal and payment processing is performed for other customers' digital cash forms 25 and 27, with digital cash payment data 33 being retailed from digital cash form 25 and digital cash payment data 34 being retailed from digital cash form 27. Handed over to store-specific digital cash form 29. Even in the case of the retail store-specific digital cash form 29, the digital cash balance data 35 is usually already filled in. Digital cash payment data 32, digital cash payment data 33, and digital cash payment data 34 are used as arguments in the slot that is the entry field of the digital cash form 29 by a message instructing to add to the digital cash balance data 35. Delivered, digital cash payment data 32, digital cash payment data 33 and digital cash payment data 34 are added to the digital cash balance data 35 to create a new instance with the amount in the digital cash form entry field changed. ..
In normal object-oriented programming, an argument is passed to a slot by a message to create a new instance, not the entire newly created instance. However, in the case of digital cash, cryptographic technology is used for security reasons, so it is possible to create an instance in which digital cash payment data is entered at the payment source, encrypt this instance, and deliver it to the payee.
An example of a trading system performed by transferring a digital cache via a communication network will be described with reference to FIG. This embodiment utilizes the system configuration shown in FIG. 4, in which 36 is the customer, 37 is the customer 36's bank, 38 is the retail store, 39 is the retail 38's bank, 40. Is a maker, 41 is a trading bank of maker 40, 8 is a communication network such as a public line provided by a telecommunications carrier or a CATV line provided by a cable television carrier, and is a communication network such as a customer 36, a customer's bank 37, and a retail store. 38, retailer's bank 39, maker 40 and maker's bank 41 can be connected to each other by communication network 8. In this system, the customer 36 can use a credit company that provides cash advance services in addition to the bank, and can intervene an appropriate number of wholesale stores between the retail store and the manufacturer. In addition, 42 and 43 are IC cards or PC cards that store digital cache data, and are used when the communication network is not used. In this figure, the dashed line shows the encrypted digital cache data path, and the solid line shows the request path from the customer, retailer, or manufacturer to the bank. The chain line shows the private key route from each bank. Further, in this embodiment, the first private key prepared by the customer bank 37, the second private key generated by the customer, the third private key generated by the retail store, and the fourth private key generated by the manufacturer are used as the encryption keys. Be done. In this embodiment, the customer side bank 37, the retail store side bank 39, and the manufacturer side bank 41 are described as separate ones, but these may be collectively considered as a financial system.
The digital cache management program P that encrypts / decrypts the digital cache data is distributed in advance to the customer 36 and stored in the user terminal device. The digital cash management program P can also be transferred with data each time a transaction is made with a bank. Furthermore, it is desirable that the digital cash management program P be common to all banks. The customer 36 applies to the customer bank 37 to withdraw the deposit from the deposit account by specifying the amount via the communication network 8 using the user terminal device. At this time, the customer information Ic of the customer 36 To present.
The customer bank 37, which receives the deposit withdrawal application from the customer 36, selects or creates the first private key Ks1, encrypts the digital cash data M0 of the withdrawal amount with this first private key Ks1, and Cm0ks1 = E (Ks1). , M0) The encrypted digital cache data Cm0ks1 and the first private key Ks1 which is the decryption key are transferred to the customer 36, and the customer information Ic and the first private key Ks1 are stored. In this case, the first private key Ks1 may be selected from those prepared in advance by the customer bank 37, but the customer presents the customer information Ic at the time of withdrawal, and the customer information Ic presented by the digital cash management program P. It can also be created based on. Ks1 = P (Ic) In this way, not only can the first private key Ks1 be unique to the customer 36, but there is no need to transfer the first private key Ks1 to the customer 36. , The safety of the system is increased. The first private key Ks1 can also be created based on the bank information Ibs or bank information Ibs of the customer bank 37 and the creation date and time.
The customer 36 to whom the encrypted digital cache data Cm0ks1 and the first private key Ks1 are transferred uses the second private key based on either one or both of the customer information Ic and the first private key Ks1 by the digital cache management program P. Ks2 is generated, and Ks2 = P (Ic) The generated second private key Ks2 is stored in the user terminal device. In addition, the customer 36 decrypts the encrypted digital cache data Cm0ks1 using the first private key Ks1 by the digital cache management program P and confirms the contents of M0 = D (Ks1, Cm0ks1). When the digital cache data M0 is stored in the user terminal device which is an electronic wallet, it is encrypted by the digital cache management program P using the generated second private key Ks2. Cm0ks2 = E (Ks2, M0) At this time, the first private key Ks1 is discarded.
The customer 36 who wishes to purchase goods from the retail store 38 decrypts the encrypted digital cache data Cm0ks2 stored in the user terminal device which is an electronic wallet by the digital cache management program P using the second private key Ks2. M0 = D (Ks2, Cm0ks2) Digital cache data M1 corresponding to the required amount is encrypted by the digital cache management program P using the second private key Ks2, and Cm1ks2 = E (Ks2, M1) via the communication network 8. Payment is made by transferring the encrypted digital cache data Cm1ks2 to the user terminal device, which is the electronic wallet of the retail store 38. At this time, the customer information Ic is also transferred to the user terminal device of the retail store 38. The remaining amount digital cache data M2 is encrypted by the digital cache management program P using the second private key Ks2, and is stored in the user terminal device of Cm2ks2 = E (Ks2, M2) customer 36.
The retail store 38 to which the encrypted digital cache data Cm1ks2 and the customer information Ic have been transferred stores the transferred encrypted digital cache data Cm1ks2 and the customer information Ic in the user terminal device and confirms the contents of the communication network 8 Present the customer information Ic to the retail store bank 39 via the above, and request the transfer of the second private key Ks2, which is the decryption key. Upon receiving the transfer request of the second private key Ks2 from the retail store 38, the retail store bank 39 transfers the customer information Ic to the customer bank 37 together with the transfer request of the second private key Ks2. The customer bank 37 to which the transfer request of the second private key Ks2 is transferred from the retailer bank 39 uses the digital cash management program P to obtain the customer information Ic if the second private key Ks2 is based only on the customer information Ic. The second private key Ks2 is generated based on the above, and if the second private key Ks2 is based on the customer information Ic and the first private key Ks1, the digital cache management program P is used to convert the customer information Ic and the first private key Ks1. Based on this, the second private key Ks2 is generated, and the generated second private key Ks2 is transferred to the retail bank 39. The retailer bank 39 to which the second private key Ks2 has been transferred from the customer bank 37 transfers the second private key Ks2 to the retailer 38 via the communication network 8.
The retail store 38 to which the second private key Ks2 has been transferred decrypts the encrypted digital cache data Cm1ks2 using the second private key Ks2 by the digital cache management program P, and confirms the amount of M1 = D (Ks2, Cm1ks2). Above, ship the goods to customer 36. In this case, the retail store 36 may request the transfer of the second private key Ks2 directly to the customer bank 37 instead of the retail store bank 39.
When the digital cash received by the retail store 38 is deposited into the account of the retail store bank 39, the customer information Ic is transferred to the retail store bank 39 via the communication network 8 together with the encrypted digital cash data Cm1ks2. The retail bank 39 to which the encrypted digital cache data Cm1ks2 and the customer information Ic have been transferred requests the customer bank 24 to transfer the second private key Ks2 by transferring the customer information Ic. The customer bank 37 requested to transfer the second private key Ks2 by the retailer bank 39 uses the digital cash management program P to transfer the second private key Ks2 to the customer information Ic if the second private key Ks2 is based only on the customer information Ic. Generates the second private key Ks2 based on it, and if the second private key Ks2 is based on the customer information Ic and the first private key Ks1, the digital cache management program P is based on the customer information Ic and the first private key Ks1. The second private key Ks2 is generated, and the generated second private key Ks2 is transferred to the retail bank 39. The retailer bank 39 to which the second private key Ks2 is transferred from the customer bank 37 decrypts the encrypted digital cache data Cm1ks2 using the second private key Ks2 by the digital cache management program P, and M1 = D (Ks2). , Cm1ks2) Deposit the decrypted digital cash data M1 to the bank account of the retail store 39.
In a general trading system, the retail store 38 purchases goods from the maker 40 or a wholesale store between the maker 40 and the retail store 38 and sells them to the customer 36. Therefore, a transaction form similar to that existing between the customer 36 and the retail store 38 exists between the retail store 38 and the manufacturer 40. The handling of digital cash performed between the retail store 38 and the manufacturer 40 is basically the same as the handling of digital cash performed between the customer 36 and the retail store 38, so it is explained in order to avoid complications. Is omitted.
Since all digital cash handling in this digital cash system is performed through a bank, by storing information such as the amount, date, and private key requester information related to the handling of digital cash in the customer's bank, It is possible to grasp the balance and usage history of the digital cache. In addition, even if the user terminal device, which is an electronic wallet that stores digital cache data, becomes unusable due to loss or damage, the digital cache should be reissued based on the usage balance and usage history stored in the customer's bank. Is possible. It is desirable to add a digital signature to the digital cache data in order to improve the security of the digital cache. In this embodiment, customer information is added to the digital cache, and this customer information may be digitally signed. That is, in this embodiment, the digital cash also has a function as a bill settlement system with the customer as the originator. Furthermore, this system can also be applied to various payment systems using letters of credit, shipping securities, etc. in international trade, which are conventionally performed using paper.
[Example 18] All the handling of digital cash in the digital cash system described in Example 17 is performed with the intervention of a bank, but since it is also possible to handle the digital cash without the intervention of a bank, the following , Explain a digital cash system that does not involve a bank. In this digital cache system, a public key and a private key are used as the encryption key for encrypting the digital cache data, and the private key Ks and the customer information Ic used in the 17th embodiment are not used. Therefore, in this embodiment, the digital cash is used in a form similar to money. Since the points other than these are the same as the system configuration of the seventeenth embodiment, specific description thereof will be omitted.
Each bank, customer, retail store, and manufacturer related to this digital cash system, who will receive the digital cash, prepares a public key and a private key. The public key in it can be sent to the prospective payer in advance, or can be sent to the payer before the transaction is made, but here, it is assumed that the public key is distributed to the prospective payer in advance. The customer 36 applies to the customer bank 37 to withdraw the deposit from the deposit account by designating the amount via the communication network 8 using the terminal device. The customer bank 37, which receives the deposit withdrawal application from the customer 36, encrypts the digital cash data M0 of the withdrawal amount by the digital cash management program P using the customer public key Kbc sent in advance, and Cm0kbc = E (Kbc). , M0) Transfer the encrypted digital cache data Cm0kbc to the customer 36.
The customer 36 to whom the encrypted digital cache data Cm0kbc is transferred is decrypted by the digital cache management program P using the customer-specific key Kvc corresponding to the customer public key Kbc, and the contents of M0 = D (Kvc, Cm0kbc) are confirmed. If there is balance data M1 in the terminal device, the balance data is changed to M2 (= M0 + M1), and the digital cache data M2 with the changed amount is converted to the customer public key Kbc by the digital cache management program P. Encrypt with and save in the Cm2kbc = E (Kbc, M2) terminal device.
The customer 36 who wishes to purchase goods from the retail store 38 decrypts the encrypted digital cache data Cm2kbc stored in the terminal device by the digital cache management program P using the customer-specific key Kvc, and M2 = D (Kvc, Kvc, Cm2kbc) Digital cache data M3 corresponding to the required amount is encrypted by the digital cache management program P using the retail store public key Kbs sent in advance, and retailed via Cm3kbs = E (Kbs, M3) communication network 8. Payment is made by transferring to the terminal device of store 38. The remaining digital cache data M4 (= M2-M3) is encrypted with the customer public key Kbc by the digital cache management program P and stored in the Cm4kbc = E (Kbc, M4) terminal device.
The retail store 38 to which the encrypted digital cache data Cm3kbs is transferred decrypts the contents of M3 = D (Kvs, Cm3kbs) by the digital cache management program P using the retail store dedicated key Kvs corresponding to the retail store public key Kbs. Check, if there is balance data M5 in the terminal device, change the balance data to M6 (= M5 + M3), and retail the digital cache data M6 with the changed amount by the digital cache management program P. Encrypt with the store public key Kbs and save it in the Cm6kbs = E (Kbs, M6) terminal device.
The retail store 38, which intends to settle the purchase price of the product to the manufacturer 40, also makes the payment in the same manner. Further, the payment to the customer side bank 37 of the customer 36, the payment to the retail store side bank 39 of the retail store 36, and the payment to the maker side bank 41 of the maker 40 are performed in the same manner.
In the 17th and 18th embodiments described above, the configuration of the data copyright management system described with reference to FIG. 4 is applied in order to realize the digital cache system, and the customer information is used in the 17th embodiment. However, the private key used is changed, and the public key and the private key are used in Example 18. However, as the system configuration for realizing the digital cache system, other copyright management system configurations, that is, the data copyright management system shown in FIG. 1, the data copyright management system shown in FIG. 2, and FIG. 3 Both the configuration of the data copyright system shown in FIG. 5 and the data copyright system shown in FIG. 5 can be applied. Further, as the encryption key method used in that case, the private key that does not change, the public key and the private key, the combination of the private key and the public key and the private key, and the duplication of the key are described in Examples 1 to 13. Any of the cryptographic key methods described can be applied.
[Example 19] A television conferencing system, which has been merely a conventional voice telephone with television images added, has recently been incorporated into a computer system to improve the quality of audio or video. However, it is evolving so that data on a computer can be handled at the same time as audio and video. Under these circumstances, the security against privacy infringement and data leakage of users due to eavesdropping other than television conference participants is protected by an encryption system using a private key. However, since the conference content obtained by the television conference participants themselves is decrypted, the television conference participants themselves save the conference content, process it in some cases, and even the television conference participants themselves. The privacy and data security of other television conference participants is completely unprotected if secondary use is made to distribute to anyone other than. In particular, as a result of the development of transmission data compression technology and the increase in the capacity of data storage media, there is a real risk that the entire contents of a television conference will be copied to the data storage medium or even transferred via a network. Is becoming.
In view of this situation, this embodiment applies the configuration of the data copyright management system described so far to the television conference system, and by applying the configuration of the data copyright management system to the television conference system, the television conference participants themselves can use the data copyright management system as a secondary use. It ensures the privacy and data security of television conference participants.
In this television conference data management system, for example, the database 1 in the configuration of the data copyright management system shown in FIG. 4 is used as the first participant of the television conference, and the primary user terminal device 4 is used as the second participant of the television conference. In addition, it can be realized by replacing the secondary user terminal device 5 with a non-participant in the television conference. This embodiment will be described with reference to FIG. In this figure, 44 is the first participant of the television conference, 45 is the second participant of the television conference, 46 is the third non-participant of the television conference, 47 is the fourth non-participant of the television conference, and 8 is the telecommunications business. It is a communication network such as a public line provided by a person or a CA television line provided by a cable television operator, and the first participant 44 of the television conference and the second participant 45 of the television conference are mutually provided by the communication network 8. It is said that it can be connected. In addition, the second participant 45 of the television conference and the third non-participant of the television conference 46, the third non-participant of the television conference 46 and the fourth non-participant of the television conference 47 can be connected by the communication network 8. There is. Moreover, 48 is a data recording medium. In this figure, the broken line shows the route of the encrypted television conference content, and the solid line shows the television conference 3rd non-participant 46 and the television conference 4th non-participant 47. Is the route to request the encryption key from the first participant of the television conference, and the one-point chain line shows from the first participant of the television conference 44 to the second participant of the television conference 45, the third of the television conference. This is the route by which the encryption key is transferred to the non-participants 46 and the fourth non-participant 47 of the television conference. In the television conference data management system described in this embodiment, in order to simplify the explanation, a case where only the privacy and data security of the first participant 44 of the television conference are ensured will be described. Needless to say, it is possible to ensure the privacy and data security of the second participant 45 of the conference.
The television conference management program P, which encrypts / decrypts the television conference data of the television conference first participant 44 including video and audio, is the television conference second participant 45, the television conference third non-participant 46. And, it is distributed in advance to the 4th non-participant 47 of the television conference, and is built in each terminal device. The television conference data management program P can also be transferred every time the encryption key is transferred. Further, in this embodiment, the first private key prepared by the first participant 44 of the television conference and the second private key generated by the second participant 45 of the television conference as the encryption key, and the third non-participant 46 of the television conference The third private key generated by is used.
The first participant 44 of the television conference and the second participant 45 of the television conference use each terminal device, and the audio, video, and data (these are collectively referred to as "television conference data") via the communication network 8. The television conference is conducted by transferring (referred to as) to each other, but before the television conference is started, the first participant 44 of the television conference selects or generates the first private key Ks1 and the first private key Ks1. To the second participant 45 of the television conference before starting the television conference. In addition, the second participant 45 of the television conference to which the first private key Ks1 has been transferred generates the second private key Ks2 based on the first private key Ks1 by the television conference data management program P, and Ks2 = P ( Ks1) Save the generated second private key Ks2 in the terminal device.
The first participant 44 of the television conference encrypts the television conference data M0 with the first private key Ks1 and Cm0ks1 = E (Ks1, M0) encrypted in the television conference conducted via the communication network 8. Transfer the television conference data Cm0ks1 to the second participant 45 of the television conference.
Upon receiving the television conference data Cm0ks1 encrypted using the first private key Ks1, the second participant 45 of the television conference decrypts the encrypted television conference data Cm0ks1 using the first private key Ks1 and M0. = D (Ks1, Cm0ks1) Use the decrypted television conference data M0. In addition, the television conference data management program P generates a second private key Ks2 based on the first private key Ks1. Ks2 = P (Ks1)
When the decrypted television conference data M0 is stored in the terminal device of the television conference second participant 45, when copied to the data recording medium 48, the television conference third non-third via the communication network 8. When transferred to a participant, the data M is encrypted by the television conference data management program P using the second private key Ks2. Cmks2 = E (Ks2, M)
The encrypted data Cmks2 is copied to the recording medium 11 together with the television conference data name or the television conference data number, or is supplied to the third non-participant of the television conference via the communication network 8.
The third non-participant of the television conference who obtained the encrypted data Cmks2 uses the terminal device to specify the television conference data name or the television conference data number for the secondary use of the television conference data M. Apply for the first participant 44 of the television conference.
The first participant 44 of the television conference who received the secondary use application of the data M searches for the first private key Ks1 using the television conference data name or the television conference data number as a clue, and based on the first private key Ks1. The second private key Ks2 is generated, and Ks2 = P (Ks1) The generated second secret key Ks2 is supplied to the third non-participant 46 of the television conference.
The television conference third non-participant 46 who received the second private key Ks2 decrypts the encrypted data Cmks2 using the television conference data management program P using the second private key Ks2 and M = D ( Ks2, Cmks2) Use the decrypted television conference data M. When the television conference data M is stored in the terminal device of the television conference third non-participant 46, when copied to the recording medium 49, the television conference fourth non-participant 47 via the communication network 8. When transferred to, the television conference data M is encrypted by the television conference data management program P using the second private key Ks2. Cmks2 = E (Ks2, M)
Furthermore, the television conference data management program P generates a third private key Ks3 based on the second private key Ks2, and the Ks3 = P (Ks2) television conference data management program P generates this generated third private key. Data M can also be encrypted using Ks3. Cmks3 = E (Ks3, M)
In the 19th embodiment described above, the configuration of the data copyright management system described with reference to FIG. 4 is applied to realize the television conference data management system, and the private key used is changed. However, as the system configuration for realizing the television conference data system, there are other system configurations, that is, the system configuration shown in FIG. 1, the system configuration shown in FIG. 2, the system configuration shown in FIG. 1, and the figure. Both the system configuration shown in 3 and the system configuration shown in Fig. 5 can be applied. Further, as the cryptographic key method used in that case, the private key that does not change, the public key and the private key, the combination of the private key and the public key and the private key, and the duplication of the key are described in Examples 1 to 13. The described encryption key method can be applied.
In addition, this explanation assumes that the second participant of the television conference saves and uses the television conference data and copies it to a recording medium or transfers it to a recording medium via a communication network, but it is used for encryption. These actions can also be restricted by ensuring that the compromised encryption key is immediately destroyed.
[Example 20] As described above, each user who uses the system of the present invention needs to be registered in the database organization in advance, and at the time of this registration, the database software is applied to the user. Provided. Since this software includes a program for decrypting a copyright management program using the first encryption key in addition to normal communication software such as a data communication protocol, it is necessary to protect it. Further, in the present invention, in order to use the data M, the first encryption key K1, the second encryption key K2, and the copyright management program P are transferred to each user, and each user needs to store them. is there. Furthermore, a program including a copyright information label, user information, a public key of a public key system, a private key, and a private key generation algorithm is stored as needed.
The most convenient means is to use a flexible disk as a means of storing these, but the flexible disk is extremely vulnerable to data loss or falsification. Also, when using a hard disk drive, there is concern about data loss or falsification, although not as much as with a flexible disk. By the way, recently, IC cards in which IC elements are enclosed in card-shaped containers have become widespread, and in particular, PC cards in which a microprocessor is enclosed are being standardized as PCMCIA cards or JEIDA cards.
FIG. 10 shows an example in which the user terminal device of the database copyright management system of the present invention is configured by using this PC card. In this figure, 50 is the microprocessor of the main body of the user terminal device, and 51 is the system bus. In addition, 52 is a PC card in which a PC card microprocessor 53, a read-only memory 55, and a write / read memory 56 are enclosed and these are connected by a PC card microprocessor bus 54.
The read-only memory 55 stores fixed information such as database software and user data in the database organization. The read-only memory 55 also stores the first encryption key, the second encryption key, and the copyright management program supplied from the key management center 9 or the copyright management center. Since the read-only memory 55 is also written, it is most convenient to use EEPROM.
As explained earlier, the data, the first encryption key K1, the second encryption key K2, the third encryption key K3 ..., and the copyright management programs P1, P2, P3 ... are all in an encrypted state. The first encryption key K1, the copyright management program P, the data M, and the second encryption key K2 must be decrypted in order to be supplied to the user and use the data. These operations may be performed by the microprocessor 50 of the user terminal device main body using the software stored in the read-only memory 55 of the PC card 52, the first encryption key K1, and the copyright management program P1. Since these data are transferred to the user terminal device, there is a risk of unauthorized use. In order to avoid this danger, the microprocessor 53 in the PC card 52 performs all the work using the write / read memory 56 via the CPU bus 54, and only the result is transferred to the user terminal device for various uses. Try to do it. When this PC card is used, a different device can be used as a user terminal device. In addition to the PC card, a board or an external device having these functions can also be used.
The present embodiment also discloses the invention described below. (Appendix 1) A data copyright management system that manages the copyright of data that is encrypted and supplied to users from the database: The data copyright management system has database 1 and key management center 9. The decryption key of the encrypted data is supplied from the key management center 9 to the user; when the user displays or processes the data, the encrypted data is decrypted using the decryption key. A data copyright management system in which the data is re-encrypted when the user stores, copies or transfers the data or the processed data. (Appendix 2) The data copyright management system according to Appendix 1, wherein the encryption key used for the re-encryption is an encryption key different from the decryption key. (Appendix 3) The data copyright management system described in Appendix 3 in which the copyright management program is stored in the ROM of the device used by the user. (Appendix 4) The data copyright management system described in Appendix 3 in which the copyright management program is stored in a system area managed by the operating system of the device used by the user. (Appendix 5) Further, the data copyright management system described in Appendix 1 or Appendix 2 in which a copyright management program for managing the copyright of the data is used. (Appendix 6) Further, the data copyright management system described in Appendix 1, Appendix 2, Appendix 3, Appendix 4 or Appendix 5 in which unencrypted copyright information regarding the copyright of the data is used. (Appendix 7) When the unencrypted copyright information is added to the encrypted data as a copyright information label and the data is stored, copied or transferred, the copyright information label is attached as described above. The data copyright management system described in Appendix 1, Appendix 2, Appendix 3, Appendix 4, Appendix 5 or Appendix 6 that is stored, copied or transferred together with the data. (Appendix 8) The data copyright management system described in Appendix 7 in which the copyright information label is digitally signed. (Appendix 9) A data copyright management system for using data encrypted and supplied from a database to users: The data copyright management system consists of a database 1, a key management center 9, and a copyright management center 10. The data copyright management system uses a private key, user information, and a copyright management program; the database 1 encrypts data with the first private key to communicate network 8, communication / broadcasting satellite 2, and recording medium. It is distributed to the primary user 4 via 3; the primary user 4 presents the primary user information to the key management center 9 and makes a usage request; the key management center 9 makes the primary user information. Is transferred to the copyright management center 10; the key management center 9 transfers the copyright management program together with the first private key and the second private key to the primary user 4 via the communication network 8; The primary user 4 decrypts and uses the encrypted data using the first private key by the copyright management program; the copyright when the decrypted data is stored, copied or transferred. A data copyright management system in which unencrypted primary user information is added to the re-encrypted data that is copied or transferred while being re-encrypted using the second private key by the management program. (Appendix 10) When the decrypted data is copied or transferred, the first private key and the second private key are discarded by the copyright management program; the primary user 4 who reuses the encrypted data is the above. Apply to the Copyright Management Center 10 to re-transfer the second private key for reuse of the re-encrypted data; the data copyright management system described in Appendix 9 in which the second private key is re-transferred. (Appendix 11) The data copyright management system according to Appendix 10, wherein a copy or transfer of the encrypted data is registered in the copyright management center 10 when the second private key is re-transferred. (Appendix 12) The secondary user 5 presents the primary user information to the copyright management center 10 and makes a usage request; The copyright management center 10 transfers the second private key, the third private key, and the copyright management program to the secondary user 5 after confirming the retransfer of the second private key to the primary user 4. The secondary user 5 decrypts the encrypted data using the second private key by the copyright management program; the copyright management when the decrypted data is stored, copied or transferred. The data copyright management system according to Appendix 10 or Appendix 11, wherein the program performs re-encryption and re-decryption using the third private key. (Appendix 13) The second private key is generated by the copyright management program based on any one or several of the first private key, the user information, and the number of times the copyright management program has been used. 9, Appendix 10, Appendix 11 or Appendix 12 data copyright management system. (Appendix 14) A data copyright management system for using the data encrypted and supplied from the database to the user: The data copyright management system includes database 1, key management center 9, and copyright management center. It is composed of 10; the private key, user information and copyright management management program are used in the data copyright management system; the primary user 4 presents the primary user 4 information to the database 1 and requests the use of data. The database 1 encrypts the requested data using the first private key, and the first secret key, the second secret key, and the copyright management program are used together with the communication network 8. Transfer to the primary user 4; the key management center 9 transfers the primary user information to the copyright management center 10; the key management center 9 manages the copyright together with the first private key and the second private key. The program is transferred to the primary user 4 via the communication network 8; the primary user 4 decrypts and uses the encrypted data using the first private key by the copyright management program; When the decrypted data is stored, copied or transferred, it is re-encrypted by the copyright management program using the second private key and encrypted into the re-encrypted data to be copied or transferred. A data copyright management system to which no primary user information is added. (Appendix 15) When the decrypted data is copied or transferred, the first private key and the second private key are discarded by the copyright management program; when the encrypted data is reused, the primary user 4 applies to the copyright management center 10 for re-transfer of the second private key for reuse of the re-encrypted data; the data copyright management system described in Appendix 14 in which the second private key is re-transferred. .. (Appendix 16) The data copyright management system according to Appendix 15, wherein a copy or transfer of the encrypted data is registered in the copyright management center 10 when the second private key is re-transferred. (Appendix 17) The secondary user 5 presents the primary user information to the copyright management center 10 and makes a usage request; the copyright management center 10 makes the usage request to the primary user 4. After confirming the retransfer of, the second private key, the third private key, and the copyright management program are transferred to the secondary user 5. The secondary user 5 uses the copyright management program to transfer the second secret. The encrypted data is decrypted using the key; when the decrypted data is stored, copied or transferred, the copyright management program re-encrypts and re-decrypts the encrypted data using the third private key. The data copyright management system described in Appendix 15 or Appendix 16 that is carried out. (Appendix 18) The second private key is generated by the copyright management program based on any one or several of the first private key, the user information, and the number of times the copyright management program is used. 14, Appendix 15, Appendix 16 or Appendix 17 data copyright management system. (Appendix 19) A data copyright management system for using the data encrypted and supplied from the database to the user: The data copyright management system consists of a database 1, a key management center 9 and a copyright management center 10; the data copyright management system uses a private key, a public key and a private key; the primary user 4 is the key. The first public key, the second public key, and the primary user information are presented to the management center 9 to request the use of the desired data; the database 1 that receives the use request uses the data as the first private key. The first private key is encrypted using the first public key, the second private key is encrypted using the second public key, and the encrypted data and the encrypted first secret are used. The key and the encrypted second private key and the copyright management program are transferred to the primary user 4; the primary user 4 uses the encrypted first private key by the copyright management program to use the first dedicated key. The encrypted data is decrypted using the decrypted first private key, the encrypted second private key is decrypted using the second dedicated key, and the decrypted data is stored, copied, or A data copyright management system in which the copyright management program performs encryption and decryption using the second private key when transfer is performed. (Appendix 20) When the decrypted data is copied or transferred, the first private key and the second private key are discarded by the copyright management program; the primary user 4 who reuses the encrypted data is the above. Apply to the Copyright Management Center 10 to retransfer the second private key for reuse of the re-encrypted data; the data copyright management system according to Appendix 19, wherein the second private key is re-transferred. (Appendix 21) The data copyright management system according to Appendix 20, wherein a copy or transfer of the encrypted data is registered in the copyright management center 10 when the second private key is re-transferred. (Appendix 22) The secondary user 5 presents the primary user information to the copyright management center 10 and makes a usage request; The copyright management center 10 transfers the second private key, the third private key, and the copyright management program to the secondary user 5 after confirming the retransfer of the second private key to the primary user 4. The secondary user 5 decrypts the encrypted data using the second private key by the copyright management program; the copyright management when the decrypted data is stored, copied or transferred. The data copyright management system according to Appendix 20 or Appendix 21, wherein the program performs re-encryption and re-decryption using the third private key. (Appendix 23) The second private key is generated by the copyright management program based on any one or several of the first private key, the user information, and the number of times the copyright management program has been used. 19, Appendix 20, Appendix 21 or Appendix 22 Data copyright management system. (Appendix 24) A data copyright management system for using multiple data that are encrypted with different encryption keys and supplied to users from database 1: The data copyright management system uses encryption keys. Person information and copyright management programs are used; the primary user 4 obtains a plurality of copyright management programs and a plurality of primary encryption keys specific to the plurality of original data from the copyright management center 10 and obtains the plurality of originals. The data is decrypted with the plurality of first encryption keys; one or more second encryption keys are generated by the plurality of copyright management programs unique to the plurality of original data; the plurality of original data or plural used. The processed data is encrypted with the one or more second encryption keys by the plurality of copyright management programs unique to the plurality of original data, and stored / copied / transferred together with the processing process data; The plurality of original data or the plurality of processed data encrypted with the one or a plurality of second encryption keys are the plurality of copyright management programs obtained by the secondary user 5 from the copyright management center 10. A data copyright management system that is decrypted with the one or more second encryption keys, processed using the processing process data, and used. (Appendix 25) The second private key is generated by the copyright management program based on any one or several of the first private key, the user information, and the number of times the copyright management program has been used. 24 listed data copyright management system. (Appendix 26) A data copyright management system for using data encrypted and supplied from database 1 to users: The data copyright management system manages encryption keys, user information, and copyright management. The program is used; the user presents user information to the database 1; the database 1 supplies the first user with the data encrypted with the first encryption key; the first user. Generates a second encryption key based on the first encryption key using the copyright management program; when the first user uses the encrypted data, the first encryption key is used. The encrypted data is decrypted; when the first user saves, copies or transfers the decrypted data, the decrypted data is re-encrypted using the second encryption key, data copyright. Management system. (Appendix 27) The data copyright management system described in Appendix 26, wherein the encryption key is a private key. (Appendix 28) The data copyright management system described in Appendix 26, wherein the encryption key is a public key and a private key. (Appendix 29) A digital cache management system for using an encrypted digital cache supplied from a financial institution to a first user: in the digital cache management system, decryption of the encrypted digital cache data. The key is supplied by the financial institution to the first user; When the first user confirms the digital cache data, the encrypted digital cache data is decrypted by using the decryption key; when the first user stores the decrypted digital cache data, the decryption key is used to decrypt the encrypted digital cache data. A digital cache management system in which the data is re-encrypted when the modified digital cache data is stored or when the digital cache data is transferred to a second user. (Appendix 30) The digital cache management system of Appendix 29, wherein the encryption key used for the re-encryption is an encryption key different from the decryption key. (Appendix 31) Further, the digital cache management system of Appendix 29 or Appendix 30 in which the digital cache management program for managing the digital cache is used. (Appendix 32) Further, the digital cache management system of Appendix 29, Appendix 30 or Appendix 31 in which unencrypted first user information is used. (Appendix 33) When the unencrypted first user information is added to the encrypted digital cache data as the first user information label and the digital cache data is saved, the modified digital cache The digital cache management system of Appendix 29, Appendix 30, Appendix 31 or Appendix 32, which is stored or transferred together with the digital cache data when the data is stored or when the digital cache data is transferred to the second user. .. (Appendix 34) The data copyright management system described in Appendix 33, wherein the first user information label is digitally signed. (Appendix 35) A digital cache management system for using the digital cache that is encrypted and supplied to the first user from the financial institution: The digital cache management system manages the encryption key, user information, and digital cache. The program is used; the first user presents the first user information to the financial institution; The financial institution supplies the first user with the digital cache encrypted with the first encryption key; the first user uses the digital cache management program to use a second encryption key based on the first encryption key. An encryption key is generated; when the first user confirms the encrypted digital cache data, the encrypted digital cache data is decrypted using the first encryption key; the user decrypts the encrypted digital cache data. When the digital cache data is stored, it is re-encrypted using the second encryption key; when the decrypted digital cache data is transferred to the second user, it is re-encrypted using the second encryption key. Then, the re-encrypted digital cache data is transferred to the second user together with the first user information; the second user presents the first user information to the financial institution; the financial institution The second encryption key based on the first user information is generated and transferred to the second user; the second user uses the transferred second encryption key to use the transferred second encryption key and transfers the second encryption key to the second user. A digital cache management system that decrypts re-encrypted digital cache data. (Appendix 36) The digital cache management system of Appendix 35, wherein the encryption key is a private key. (Appendix 37) The digital cache management system of Appendix 35, wherein the encryption key is a public key and a private key. (Appendix 38) A digital cash management system for using an encrypted digital cache supplied from a financial institution to a first user: the digital cash management system uses a public key and a private key; The first user presents the first public key to the financial institution; the financial institution encrypts digital cache data with the first public key and supplies it to the first user; the first user is said to The digital cache data is decrypted using the first dedicated key; the second user presents the second public key to the first user; the first user presents the decrypted digital cache data to the first. 2 Encrypt with public key and transfer to second user; The second user is a digital cache management system that decodes the digital cache data using a second dedicated key. (Appendix 39) A television conference data management system for using the television conference data encrypted and supplied from the first user to the second user: In the television conference data management system, The decryption key of the encrypted television conference data is supplied from the first user to the second user; when the second user uses the television conference data, the encryption using the decryption key is used. The television conference data is decrypted; the second user saves the decrypted television conference data, the processed television conference data is saved, or the television conference data is sent to the third user. A television conference data management system in which the data is re-encrypted when transferred. (Appendix 40) The television conference data management system of Appendix 39, wherein the encryption key used for the re-encryption is an encryption key different from the decryption key. (Appendix 41) Further, the television conference data management system of Appendix 39 or Appendix 40, wherein the television conference data management program for managing the television conference data is used. (Appendix 42) In addition, the television conference data management system of Appendix 39 and Appendix 340 is the television conference data management system of Appendix 41, in which unencrypted second user information is used. (Appendix 43) When the unencrypted second user information is added to the encrypted television conference data as the second user information label and the television conference data is saved, it is changed. When the television conference data is saved, or when the television conference data is transferred to the second user, it is saved or transferred together with the television conference data, Appendix 39, Appendix 40, The television conference data management system of Appendix 41 or Appendix 42. (Appendix 44) The television conference data management system of Appendix 43, wherein the first user information label is digitally signed. (Appendix 45) A television conference data management system for using the television conference data encrypted and supplied from the first user to the second user: the encryption key in the television conference data management system. , The user information and the television conference data management program are used; the second user presents the second user information to the first user; the first user presents the first user to the second user. The television conference data encrypted with the encryption key is supplied; the second user uses the television conference data management program to generate a second encryption key based on the first encryption key; the second user. 2 When the user uses the encrypted television conference data, the encrypted television conference data is decrypted using the first encryption key; the second user decrypts the decrypted television conference data. A television conference data management system in which the decrypted television conference data is re-encrypted using the second encryption key when stored, copied or transferred. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program. The television conference data management system uses an encryption key, user information and a television conference data management program; the second user presents the second user information to the first user; the first use. The person supplies the television conference data encrypted with the first encryption key to the second user; the second user uses the television conference data management program and is based on the first encryption key. Generate a second encryption key; when the second user uses the encrypted television conference data, the encrypted television conference data is decrypted using the first encryption key; the second use A television conference data management system in which when a person stores, copies, or transfers the decrypted television conference data, the decrypted television conference data is re-encrypted using the second encryption key. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program. The television conference data management system uses an encryption key, user information and a television conference data management program; the second user presents the second user information to the first user; the first use. The person supplies the television conference data encrypted with the first encryption key to the second user; the second user uses the television conference data management program and is based on the first encryption key. Generate a second encryption key; when the second user uses the encrypted television conference data, the encrypted television conference data is decrypted using the first encryption key; the second use A television conference data management system in which when a person stores, copies, or transfers the decrypted television conference data, the decrypted television conference data is re-encrypted using the second encryption key. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program. When the second user uses the encrypted television conference data, the encrypted television conference data is decrypted using the first encryption key; the second user decrypts the decrypted television conference. A television conference data management system in which when data is stored, copied or transferred, the decrypted television conference data is re-encrypted using the second encryption key. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program. When the second user uses the encrypted television conference data, the encrypted television conference data is decrypted using the first encryption key; the second user decrypts the decrypted television conference. A television conference data management system in which when data is stored, copied or transferred, the decrypted television conference data is re-encrypted using the second encryption key. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program. When the second user saves, copies, or transfers the decrypted television conference data, the decrypted television conference data is re-encrypted using the second encryption key. Management system. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program. When the second user saves, copies, or transfers the decrypted television conference data, the decrypted television conference data is re-encrypted using the second encryption key. Management system. (Appendix 46) The television conference data management system of Appendix 45, wherein the encryption key is a private key. (Appendix 47) The television conference data management system of Appendix 45, wherein the encryption key is a public key and a private key. (Appendix 48) The user terminal device is used by connecting to the system bus of the user terminal device main body, and is composed of a microprocessor, a read-only memory connected to the microprocessor bus, a write / read memory, and a rewritable read-only memory. The read-only memory stores fixed information such as database organization use software and user data, and the read-only memory contains the first encryption key, the second encryption key, and the second encryption key supplied from the key management center or the copyright management center. A data copyright management device that stores a copyright management program.
<figref num="1">The data copyright management system block diagram of Example 1, Example 2, and Example 3 of the present invention.</figref><figref num="2">The data copyright management system block diagram of Example 4 of this invention.</figref><figref num="3">The data copyright management system block diagram of Example 5, Example 6, and Example 7 of the present invention.</figref><figref num="4">The data copyright management system block diagram of Example 8, Example 9, Example 10, and Example 11 of the present invention.</figref><figref num="5">Examples of the data copyright management system of Examples 12 and 13 of the present invention.</figref><figref num="6">Explanatory drawing of data processing.</figref><figref num="7">Explanatory drawing of a digital cache system.</figref><figref num="8">The digital cache system block diagram of Example 17 and Example 18 of the present invention.</figref><figref num="9">The television conference system block diagram of Example 19 of this invention.</figref><figref num="10">Diagram of an example configuration of a user terminal device used in the data copyright management system of the present invention.</figref>
Code description
1,19,20,21 Database 2 Broadcasting / communication satellite 3 11,12,13,48,49 Recording medium 4,5,6,7 User terminal device 8 Communication network 9 Key management center 10,14,15,17, 18 Copyright Management Center 23,25,27,29 Electronic Wallet 24,26,28 Deposit Account 30,35 Balance 31 Withdrawal 32,33,34 Payment 36 Customer 38 Retail Store 40 Manufacturer 37 Customer Side Bank 39 Retail Store Side Bank 41 Manufacturer's bank 42,43 IC card 44,45 Television conference participants 46,47 Television conference non-participants 50 Microprocessor 51 System bus 52 PC card 53 PC card microprocessor 54 PC card microprocessor bus 55 Read-only Memory 56 Write / read memory
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7359511B2 | Cited by | United States of America | Applicant |
| JP2007028007A | Cited by | Japan | Examiner |
| US8364597B2 | Cited by | United States of America | Applicant |
123 members in 4 offices
Priority claims17
| Document | Office | Kind | Date |
|---|---|---|---|
| 1994237673 | Japan | – | |
| 23767394 | Japan | A | |
| 23767394 | Japan | A | |
| 1994264199 | Japan | – | |
| 26419994 | Japan | A | |
| 26419994 | Japan | A | |
| 1994269959 | Japan | – | |
| 26995994 | Japan | A | |
| 26995994 | Japan | A | |
| 2003322109 | Japan | A | |
| 1994237673 | – | – | – |
| 1994264199 | – | – | – |
| 1994269959 | – | – | – |
| JP19940237673 | – | – | – |
| JP19940264199 | – | – | – |
| JP19940269959 | – | – | – |
| JP20030322109 | – | – | – |
Members123
| Document | Office | Kind | |
|---|---|---|---|
| EP0677949A2 | European Patent Office (EPO) | A2 | |
| JPH07271865A | Japan | A | |
| EP0677949A3 | European Patent Office (EPO) | A3 | |
| EP0704785A2 | European Patent Office (EPO) | A2 | |
| EP0709760A2 | European Patent Office (EPO) | A2 | |
| EP0715241A2 | European Patent Office (EPO) | A2 | |
| EP0719045A2 | European Patent Office (EPO) | A2 | |
| JPH08185448A | Japan | A | |
| EP0719045A3 | European Patent Office (EPO) | A3 | |
| JPH08272745A | Japan | A | |
| JPH08287014A | Japan | A | |
| JPH08288940A | Japan | A | |
| US5646999A | United States of America | A | |
| US5740246A | United States of America | A | |
| US5867579A | United States of America | A | |
| EP0709760A3 | European Patent Office (EPO) | A3 | |
| EP0715241A3 | European Patent Office (EPO) | A3 | |
| EP0704785A3 | European Patent Office (EPO) | A3 | |
| US5974141A | United States of America | A | |
| US6002772A | United States of America | A | |
| US6069952A | United States of America | A | |
| US6076077A | United States of America | A | |
| US6097818A | United States of America | A | |
| US6128605A | United States of America | A | |
| US6182218B1 | United States of America | B1 | |
| US6272635B1 | United States of America | B1 | |
| US2001013021A1 | United States of America | A1 | |
| EP1133163A2 | European Patent Office (EPO) | A2 | |
| US2001027522A1 | United States of America | A1 | |
| EP1133163A3 | European Patent Office (EPO) | A3 | |
| US2002021807A1 | United States of America | A1 | |
| US2002025044A1 | United States of America | A1 | |
| US2002052850A1 | United States of America | A1 | |
| US2002059238A1 | United States of America | A1 | |
| US6408390B1 | United States of America | B1 | |
| US6424715B1 | United States of America | B1 | |
| US2002112173A1 | United States of America | A1 | |
| US6438694B2 | United States of America | B2 | |
| US6449717B1 | United States of America | B1 | |
| US6463536B2 | United States of America | B2 | |
| US2002178372A1 | United States of America | A1 | |
| US2003012385A1 | United States of America | A1 | |
| EP0677949B1 | European Patent Office (EPO) | B1 | |
| DE69530888D1 | Germany | D1 | |
| US2003144963A1 | United States of America | A1 | |
| JP2003242286A | Japan | A | |
| JP2003250136A | Japan | A | |
| EP0719045B1 | European Patent Office (EPO) | B1 | |
| EP0704785B1 | European Patent Office (EPO) | B1 | |
| DE69532028D1 | Germany | D1 | |
| DE69532153D1 | Germany | D1 | |
| EP0715241B1 | European Patent Office (EPO) | B1 | |
| DE69532434D1 | Germany | D1 | |
| JP2004072792AThis record | Japan | A | |
| US6721887B2 | United States of America | B2 | |
| DE69530888T2 | Germany | T2 | |
| US6741991B2 | United States of America | B2 | |
| US6744894B1 | United States of America | B1 | |
| DE69532028T2 | Germany | T2 | |
| DE69532153T2 | Germany | T2 | |
| US6789197B1 | United States of America | B1 | |
| JP2004303265A | Japan | A | |
| DE69532434T2 | Germany | T2 | |
| US2005262023A1 | United States of America | A1 | |
| JP2006085725A | Japan | A | |
| US7036019B1 | United States of America | B1 | |
| EP0709760B1 | European Patent Office (EPO) | B1 | |
| DE69535013D1 | Germany | D1 | |
| JP2006180562A | Japan | A | |
| EP1133163B1 | European Patent Office (EPO) | B1 | |
| EP1691315A1 | European Patent Office (EPO) | A1 | |
| EP1691316A1 | European Patent Office (EPO) | A1 | |
| DE69535161D1 | Germany | D1 | |
| EP1710997A2 | European Patent Office (EPO) | A2 | |
| EP1722548A2 | European Patent Office (EPO) | A2 | |
| JP3850058B2 | Japan | B2 | |
| JP2006325246A | Japan | A | |
| US2006282674A1 | United States of America | A1 | |
| DE69535013T2 | Germany | T2 | |
| US2007033143A1 | United States of America | A1 | |
| US2007038575A1 | United States of America | A1 | |
| US2007061267A1 | United States of America | A1 | |
| US2007079145A1 | United States of America | A1 | |
| US2007088960A1 | United States of America | A1 | |
| EP1710997A3 | European Patent Office (EPO) | A3 | |
| EP1722548A3 | European Patent Office (EPO) | A3 | |
| US2007110228A1 | United States of America | A1 | |
| DE69535161T2 | Germany | T2 | |
| US7302415B1 | United States of America | B1 | |
| JP4030486B2 | Japan | B2 | |
| JP2008090849A | Japan | A | |
| US7383447B2 | United States of America | B2 | |
| JP4099461B2 | Japan | B2 | |
| JP4101263B2 | Japan | B2 | |
| US7447914B1 | United States of America | B1 | |
| EP1722548B1 | European Patent Office (EPO) | B1 | |
| DE69535956D1 | Germany | D1 | |
| JP4386898B2 | Japan | B2 | |
| JP4431306B2 | Japan | B2 | |
| JP2010063130A | Japan | A |
36 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Dismissal of procedure [no reply to invitation to correct request for examination]JAPANESE INTERMEDIATE CODE: A072A072 | A072 | |
| Written pleaJAPANESE INTERMEDIATE CODE: A59A59 | A59 | |
| Dismissal of procedure [no reply to invitation to correct request for examination]JAPANESE INTERMEDIATE CODE: A073A072 | A072 | |
| Dismissal of procedure [no reply to invitation to correct request for examination]JAPANESE INTERMEDIATE CODE: A072A072 | A072 | |
| Written pleaJAPANESE INTERMEDIATE CODE: A59A59 | A59 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A711A711 | A711 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A711A711 | A711 | |
| Notification of resignation of power of attorneyJAPANESE INTERMEDIATE CODE: A7424RD04 | RD04 |
Numbers
- Publication
- 2004072792
- Publication, DOCDB
- 2004072792
- Publication, EPODOC
- JP2004072792
- Application
- 322109
- Application, DOCDB
- 2003322109
- Application, EPODOC
- JP20030322109
Titles2
- Japanese
- 端末装置、ディジタルキャッシュ管理システム
- English
- Terminal equipment, digital cache management system
Classification
- IPC, 11
- G06F12 14
- G06F21 10
- G06F21 60
- G06F21 62
- G06Q10 00
- G06Q20 00
- G06Q20 06
- G06Q50 00
- G06Q50 10
- G09C1 00
- H04L9 08